Security

Hardened before you get the keys.

A standard VPS hands you a bare image and a root password. Ours hands you a server that has already been through the hardening baseline we apply on client engagements - with a report to prove it.

42 checks per serverReport delivered at handoverRe-run on request
01 — At first boot

The defaults are already closed.

The baseline runs before you receive credentials. You get the report, your SSH key is installed, and only the ports you asked for are open.

  • Key-only SSHpassword authentication disabled, root login restricted
  • Default-deny firewallonly the ports you ask for are open
  • Automatic patchingunattended upgrades with scheduled reboot windows
  • Intrusion protectionfail2ban on the host, DDoS scrubbing at the edge
  • Hardening reportevery check, its result, and what we changed
hardening-report · linux-plus-tn-01 PASS
SSH password authenticationdisabled✓
Root login over SSHkey-only✓
Host firewall (nftables)default deny✓
fail2banactive · 3 jails✓
Unattended security updatesenabled✓
Monitoring agentreporting✓
Open ports (public)22, 443✓
42 checks · 0 faileddelivered 4 min after provisioning
02 — The baseline

What the 42 checks cover.

Grouped by layer. Linux servers get the full set; Windows servers get the equivalent controls where they apply.

01

Access

  • SSH key-only, root login disabled, modern ciphers
  • sudo for a named admin user, with logging
  • Console protected by MFA on your account
  • Windows: RDP restricted to allowed IPs, NLA enforced
02

Network

  • nftables default-deny inbound, explicit allow list
  • Private VLAN between your servers, not routed publicly
  • DDoS scrubbing at the edge for L3/L4 floods
  • Optional managed Sophos or FortiGate virtual edge
03

System

  • Unattended security updates with a reboot window you choose
  • sysctl kernel hardening and a minimal package set
  • auditd and time sync configured
  • Windows: automatic updates with a scheduled reboot window
04

Data

  • Held in India — servers in our Tamil Nadu datacentre
  • Portal data in Mumbai, on infrastructure hosted in India
  • Redundant storage on hardware RAID
  • Game-panel backups on Minecraft plans
05

Detection

  • fail2ban jails for SSH and common services
  • Monitoring agent for CPU, memory, disk and reachability
  • Alerts to email or WhatsApp
  • Log shipping to your own SIEM on request
06

Reporting

  • Hardening report per server, delivered at handover
  • Change log of what the baseline modified
  • Re-run of the baseline on request after major changes
  • Evidence you can hand to auditors and customers
03 — Shared responsibility

Who handles what.

Clear lines, so nothing falls between two teams.

We handlePlatform & baseline

  • Hosts, hypervisor, network and storage
  • OS hardening baseline and security patching
  • Firewall platform, private VLAN, DDoS mitigation
  • Monitoring, alerting and engineer response

You handleYour applications

  • Application code, updates and configuration
  • Accounts and keys you add to the server
  • Firewall rules you ask us to open
  • Data classification and access decisions
  • Licences for Windows and business applications

OptionalManaged by NexusSec

  • Managed Linux with a defined support scope
  • Application updates and change windows
  • Incident response and post-incident review
  • Managed Sophos / FortiGate virtual edge
  • VAPT of your server by the NexusSec team
Next step

See the report on your own server.

Every Linux server ships with its hardening report. Deploy one and read it before you open a single port.