What this means
What this means
CM Cloud uses different isolation layers depending on the service type — from dedicated VMs to filesystem virtualisation and per-app system users — so one customer's workload cannot read or interfere with another's.
Before you start
Before you start
No action needed. This article describes platform architecture for informational purposes.
Step-by-step guidance
Step-by-step guidance
- App deployment: each app runs as a unique Unix user with a dedicated port and systemd hardening (NoNewPrivileges, PrivateTmp, ProtectSystem=strict).
- Shared hosting and WordPress: CageFS kernel-level filesystem virtualisation prevents one user from seeing another's files or processes.
- Business email: Mailcow runs each component (SMTP, IMAP, spam filter, webmail) in its own Docker container.
- Cloud VPS: each customer receives a dedicated Proxmox VM with no shared kernel — full hardware-level isolation.
- Domains: managed via CentralNic with registrant-level access controls; DNS changes require authenticated portal actions.
- Read the full security overview at cmcloudhosting.com/security for additional details.
What CM Cloud support will review
What CM Cloud support will review
Support reviews isolation concerns, VPS access control questions, email separation enquiries, and requests for security documentation.
What is not automated yet
What is not automated yet
This article does not change isolation settings, modify service configuration, or enable additional security controls.
Safety note
Safety note
Reading this article does not capture payment, provision infrastructure, register or transfer domains, change DNS, write Cloudflare or WHMCS, call providers, start workers, create retries, or enable live execution.
Safe next action
Safe next action
Visit /security for a public overview, or open a support request for specific security questions.