Boring on purpose,
where it matters
Security at Locally is not a feature tier. Every plan, from the $6.99 VPS up, ships with the same protections.
Infrastructure
Full KVM isolation: your kernel, your memory, no shared containers. Redundant power and network in every facility, with hardware owned and operated by us, never resold marketplace machines.
Network & DDoS
Always-on volumetric DDoS filtering at the edge on every IP we hand you, at no extra cost. Private VLANs available between your servers in the same region.
Your data
One-click full-disk encryption at deploy. We never inspect workloads, never mount customer disks, and wipe drives with a verified multi-pass erase on cancellation.
Your account
TOTP two-factor authentication, SSH-key injection at deploy, per-scope API tokens shown once, and a full audit log of panel actions with IP and timestamp.
Payments
Cards are processed by PCI-DSS compliant providers; numbers never touch our servers. Crypto runs through our own BTCPay instance, so no third-party processor sees your wallet.
Continuity
Weekly snapshots on every plan, daily on Business tiers. Multi-carrier uplinks with sub-30-second failover, proven publicly on our status page.
Found something? Tell us first.
Report vulnerabilities to security@locally.host. We answer within 24 hours, fix confirmed issues fast, and credit researchers who want credit. Good-faith research within your own account is safe harbor: we will not pursue action against honest reports.
In scope: locally.host, api.locally.host and the client panel. Out of scope: volumetric attacks, social engineering of staff, and anything touching other customers' servers. Machine-readable details live at /.well-known/security.txt.