What this covers
CM Cloud uses different isolation layers depending on the service type — from dedicated VMs to filesystem virtualisation and per-app system users — so one customer's workload cannot read or interfere with another's.
Before you start
No action needed. This article describes platform architecture for informational purposes.
How to do it
- App deployment: each app runs as a unique Unix user with a dedicated port and systemd hardening (NoNewPrivileges, PrivateTmp, ProtectSystem=strict).
- Shared hosting and WordPress: CageFS kernel-level filesystem virtualisation prevents one user from seeing another's files or processes.
- Business email: Mailcow runs each component (SMTP, IMAP, spam filter, webmail) in its own Docker container.
- Cloud VPS: each customer receives a dedicated Proxmox VM with no shared kernel — full hardware-level isolation.
- Domains: managed via CentralNic with registrant-level access controls; DNS changes require authenticated portal actions.
- Read the full security overview at cmcloudhosting.com/security for additional details.
What our team checks
Support reviews isolation concerns, VPS access control questions, email separation enquiries, and requests for security documentation.
Next step
Visit /security for a public overview, or open a support request for specific security questions.