Could this take my website or application offline?
Every change is planned and checked in stages. We verify recovery, record a reliable check that the website or app still works, and prepare rollback. Zero downtime is not promised; risky updates and reboots require a separately approved maintenance window.
Could I get locked out of my own server?
Private WireGuard access and emergency access through the hosting provider are tested before public SSH is restricted. The agreed recovery model can also include owner-approved, exact-IP Telegram access for 15 or 30 minutes.
I already use UFW and Fail2Ban. What am I paying for?
You are not paying for two free packages. We review who can access the server and what is reachable from the internet, preserve recovery, apply only approved changes, check production after each stage, analyze 14 days of behavior, and leave evidence and a next-step plan.
What happens during the first 14 days?
We record the expected administrator access, public ports, services and protections; review real deployments and restarts; tune obvious noise; and agree the expected server state. This is a bounded observation period, not 24/7 monitoring.
Does a Telegram alert mean my server was hacked?
No. It means the expected server state changed or a high-risk signal appeared. The alert shows what changed and what to check first; the change may be expected, accidental or malicious.
Who investigates a Telegram alert?
The owner or trusted administrator receives the signal, local evidence and recommended first action. Continuous investigation, incident response and 24/7 SOC coverage are not included.
What stays in place after day 14?
Your private access, local security logging and configured alerts remain on the server. We deliver the final report and remove our own VPN access and SSH key. Ongoing review and response are separate.
Do you need my root password or private SSH key?
No. We use a revocable public SSH key and never ask you to send private keys or server passwords.
What if the server uses Docker?
We include Docker-published ports in the exposure review. Container or network redesign is quoted separately when it cannot be changed safely inside the fixed scope.
What if the server may already be compromised?
We stop routine setup work and recommend incident response or recovery. Hardening is not a safe substitute for investigating an active incident.
Can the Corporate Admin VPN protect an admin panel?
Yes, where a selected endpoint can be safely restricted on the same compatible server. Up to seven named employees receive individual WireGuard access. This does not replace application authentication, authorization, updates or security hardening.
What if the server fails the safety check?
We stop before unsafe changes, explain the blocker and do not proceed outside the agreed scope. Any reschedule, reduced scope or cancellation is confirmed in writing.