LanguageGB
Security & SSL

Platform security & isolation

Understand how CM Cloud isolates each customer's apps, email, hosting, and VPS workloads.

What this covers

CM Cloud uses different isolation layers depending on the service type — from dedicated VMs to filesystem virtualisation and per-app system users — so one customer's workload cannot read or interfere with another's.

Before you start

No action needed. This article describes platform architecture for informational purposes.

How to do it

  1. App deployment: each app runs as a unique Unix user with a dedicated port and systemd hardening (NoNewPrivileges, PrivateTmp, ProtectSystem=strict).
  2. Shared hosting and WordPress: CageFS kernel-level filesystem virtualisation prevents one user from seeing another's files or processes.
  3. Business email: Mailcow runs each component (SMTP, IMAP, spam filter, webmail) in its own Docker container.
  4. Cloud VPS: each customer receives a dedicated Proxmox VM with no shared kernel — full hardware-level isolation.
  5. Domains: managed via CentralNic with registrant-level access controls; DNS changes require authenticated portal actions.
  6. Read the full security overview at cmcloudhosting.com/security for additional details.

What our team checks

Support reviews isolation concerns, VPS access control questions, email separation enquiries, and requests for security documentation.

Next step

Visit /security for a public overview, or open a support request for specific security questions.

Contact Support