Security Policy
- Home
- Security Policy
Security Policy
Last Updated: August 30, 2026
Security is a core component of Bridge Web Host services. We use a combination of hosting infrastructure, WordPress security practices, monitoring, maintenance, and technical controls designed to reduce security risks and help protect the websites hosted with us.
This Security Policy explains our approach to website security, the responsibilities shared between Bridge Web Host and our customers, and how we respond to suspected security incidents.
1. Our Approach to Security
Bridge Web Host provides managed WordPress and WooCommerce hosting with security incorporated into the hosting environment.
Our security practices are designed to help protect against common threats such as:
- Malware
- Malicious files and scripts
- Unauthorized access
- Brute-force attacks
- Known WordPress vulnerabilities
- Compromised plugins and themes
- Suspicious website activity
- Common website attacks
- Outdated WordPress software
Security measures may operate at both the hosting infrastructure and individual website level.
2. WordPress Security Hardening
Bridge Web Host may implement security configurations appropriate for WordPress and WooCommerce websites.
Depending on the website and hosting plan, these measures may include:
- WordPress security hardening
- Administrative access protection
- Login security measures
- File and directory protections
- Appropriate file permissions
- SSL configuration
- Security plugin configuration
- Protection against common automated attacks
- Restriction of unnecessary or potentially dangerous functionality
Security configurations may vary when necessary to maintain compatibility with a customer’s website.
3. Malware Protection and Monitoring
Bridge Web Host may use server-level and website-level security tools to help identify malicious files, suspicious activity, unauthorized modifications, and other potential security threats.
When suspicious activity is identified, we may investigate the affected website and take reasonable measures to protect the customer and hosting environment.
These measures may include isolating files, restricting access, blocking malicious traffic, disabling compromised components, or temporarily limiting website functionality while an incident is investigated.
4. WordPress, Plugin and Theme Updates
Outdated software is a common source of WordPress security vulnerabilities.
Managed hosting services may include updates to:
- WordPress core
- WordPress plugins
- WordPress themes
- Security components
- Other supported website software
Updates may occasionally be delayed when immediate installation could create a known compatibility or operational problem.
Third-party software remains subject to the security, availability, development, and support practices of its respective developer.
5. SSL and Encrypted Connections
Bridge Web Host provides or configures SSL for supported hosted websites.
SSL helps encrypt information transmitted between a website and its visitors.
SSL protects data while it is being transmitted but does not, by itself, protect a website from malware, compromised credentials, vulnerable software, or other forms of attack.
6. Backups and Recovery
Bridge Web Host may maintain website and server backups as part of our hosting and business-continuity practices.
Backups may assist with recovery following certain website failures, configuration problems, data-loss events, or security incidents.
No backup system can guarantee recovery from every possible event. Customers with business-critical information are encouraged to maintain appropriate independent records or backups when necessary.
7. White-Glove Migration and Security Review
When Bridge Web Host performs a White-Glove WordPress Migration, we may review the existing website and hosting environment for apparent security or technical concerns before or during migration.
We do not intentionally introduce known malicious files into the Bridge Web Host environment.
If malware, suspicious files, compromised software, or other significant security concerns are discovered during migration, additional investigation or remediation may be required before the website is placed into production.
Our migration and review process reduces risk but should not be interpreted as a guarantee that every previously existing vulnerability, malicious file, or security issue will always be detected.
8. Customer Account Security
Customers share responsibility for protecting access to their websites and accounts.
Customers should:
- Use strong, unique passwords
- Protect administrative credentials
- Limit administrative access to trusted individuals
- Remove accounts belonging to former employees or contractors
- Use multi-factor authentication when available
- Avoid sharing passwords through insecure communication methods
- Notify Bridge Web Host promptly of suspected unauthorized access
Bridge Web Host may require password resets or other security measures when we reasonably believe credentials have been compromised.
9. Third-Party Plugins, Themes and Software
WordPress and WooCommerce websites commonly depend on software developed by third parties.
Bridge Web Host cannot guarantee the security, continued development, compatibility, or availability of every third-party plugin, theme, extension, API, or service.
We may recommend that vulnerable, abandoned, malicious, or unsupported software be updated, replaced, disabled, or removed when it presents a material security risk.
10. Compromised Websites
If a website is suspected of being compromised, Bridge Web Host may take immediate steps to protect the affected customer, our infrastructure, and other customers.
Depending on the circumstances, we may:
- Investigate suspicious activity
- Scan website files
- Review relevant logs
- Isolate suspicious or malicious files
- Restrict website or administrative access
- Disable compromised plugins or themes
- Reset credentials
- Restore appropriate backups when available
- Temporarily suspend affected services
- Recommend or perform additional remediation
Temporary restrictions may be necessary even when the customer did not cause the security incident.
Our objective in these situations is to contain the threat, determine the appropriate corrective action, and safely restore normal operation whenever reasonably possible.
11. Security Incidents Originating From a Customer Account
Customers may not knowingly use Bridge Web Host services to distribute malware, conduct attacks, send spam, operate phishing websites, or engage in other malicious activity.
Intentional abuse is governed by our Acceptable Use Policy and may result in immediate suspension or termination.
An otherwise legitimate website that becomes compromised without the customer’s knowledge will generally be treated as a security incident rather than intentional abuse.
12. Security Notifications
When Bridge Web Host identifies a significant security issue affecting a customer’s website, we may contact the customer using the contact information associated with the account.
Customers are responsible for keeping their account contact information current so important security and service notifications can be received.
13. Responsible Security Reporting
If you believe you have identified a security vulnerability affecting a website or system operated by Bridge Web Host, please report it to us rather than attempting to exploit, disrupt, or publicly expose the vulnerability.
Please provide sufficient information for us to investigate the issue.
Security concerns may be reported to:
14. No Absolute Security Guarantee
Bridge Web Host takes website security seriously, but no hosting provider, security product, server, network, or internet-connected system can guarantee complete protection against every possible threat.
New vulnerabilities, previously unknown exploits, compromised third-party software, stolen credentials, sophisticated attacks, customer actions, and other circumstances can result in security incidents despite reasonable protective measures.
Accordingly, terms such as “secure hosting,” “security,” “protection,” “hardening,” “monitoring,” and “malware protection” describe the security measures and managed services provided by Bridge Web Host. They do not constitute a guarantee that a website will never be compromised or experience a security incident.
15. Changes to This Security Policy
Bridge Web Host may update this Security Policy as our technology, infrastructure, security practices, services, or applicable requirements change.
The current version will be published on our website with an updated revision date.
16. Contact Us
Questions about website security or this Security Policy may be directed to:
Bridge Web Host
Las Vegas, Nevada
Email: help@bridgewebhost.com
Phone: 702-307-2465