Native WHM / cPanel protection AI correlation · Local evidence · No mandatory cloud
Operational sovereignty for cPanel hosting
YOORguardAI security corecPanelcPanel SecurityWHM

YOORguard at the heart of cPanel.
Security decides on evidence.

Institutional-grade server defence where AI correlates traffic, identities, services and files in real time. YOORguard then requires local evidence before challenging, blocking or restoring.

✓ Observation mode ✓ Governed enforcement ✓ IPv4 + IPv6
WHM / cPanelNative integration
AI + localContextual correlation
171Built-in checks
nftablesDedicated firewall
0Mandatory cloud
Security built for hosting

YOORguard is the security core of cPanel.

YOORguard places its defence chain beside EasyApache4, WHM and every cPanel account. Administrators govern the server; each customer receives a compartmentalised view of their own attack surface.

01

Account-scoped data

No cross-account leakage: customers only see their domains, events and quarantine.

02

Threats made understandable

Seven-day view, attacker geolocation and rDNS, plus a clear block history.

03

Accessible quarantine

Suspicious files stay visible and traceable from the customer area.

YOORguard
cPanel
Account protectionclient.example
Active
ScopeThis account only
Activity · 7 days−34%
Latest qualified eventWebshell attempt stoppedHTTP · 21:15:10
A verifiable decision chain

Observe. Correlate with AI. Qualify. Protect.

YOORguard never confuses unusual activity with a proven threat. AI puts signals into context; every automated action then passes through a local qualification gate.

01

Observe

Traffic, logs, services, files and Apache pressure are analysed continuously.

02

Correlate with AI

The engine connects timing, target, identity, service, behaviour and recurrence to reveal coherent attack scenarios.

03

Qualify

Score, local hostility, global IP checks, exclusions and probation establish the evidence.

04

Protect

Challenge, nftables block or quarantine: every action stays proportional and traceable.

Governed artificial intelligence

AI connects the signals. Local evidence keeps the final say.

The correlation engine turns isolated events into understandable attack scenarios. It prioritises risk, explains the factors retained and hands the decision to a deterministic local gate.

Never an autonomous block based on model intuition alone.
Web behaviour Identity & services Files & malware Network & reputation
YOORguard AIContextual AI engine

Temporal, behavioural and cross-service correlation

01
Qualified scenario

Explainable score · factors · scope · recurrence

02
Local evidence gate

Exclusions, trust, challenge and proportionality before any action

Complete server protection

From first signal to remediation.

A local engine covers web, services, network and files, operated natively through WHM and cPanel.

01
Firewall

Dedicated nftables, IPv4 + IPv6

An isolated YOORguard table, six escalating TTL levels and synchronisation only in Live mode.

02
Web security

Challenge first, block second

Ambiguous traffic receives a signed, IP-bound verification. Repeated bypass attempts trigger escalation.

03
Services

Brute force stopped on local proof

FTP, SMTP, SSH, mail, cPanel and MySQL are correlated without waiting for an external source.

04
Files

Detection and quarantine

A multi-rule engine, ClamAV and external adapters connect a compromised file to its network source.

05
Exposure

Controlled ports and geo-blocking

Approved ports in one place and 249 countries available, off by default with protected trust exemptions.

06
Integrity

Signed self-protection

SHA-256 vault, continuous self-healing and a version-pinned enforcement token.

Multi-surface detection engine

Threats are correlated, not merely counted.

YOORguard’s AI engine brings together web, network, authentication and file events to separate noise from an actionable attack. Evidence remains local, contextual and reversible.

Web exploitation

Hostile signatures and application context

Detection focused on attacks that truly target hosted applications, while controlling WordPress core false positives.

  • Webshells, path traversal and backdoor names
  • Installer takeovers and fake file managers
  • Exploited PrestaShop modules and deployment artefacts
  • Hostile headers, probes and sensitive paths
L7 volumetry

Distributed and concentrated floods by domain

Sliding windows separate legitimate growth from aggressive campaigns without treating Apache load as standalone evidence.

  • Concentrated and distributed analysis per domain
  • Apache pressure used as a contextual accelerator
  • Correlation with already-proven hostility
  • Challenge before blocking ambiguous traffic
Identity & services

Cross-service brute force and credential spray

Authentication bursts and protocol probes are correlated across FTP, SMTP, SSH, mail, MySQL and cPanel.

  • Failure bursts and credential spraying
  • Hostile correlation across several services
  • Direct blocking once local evidence is acquired
  • Progressive TTL based on severity and recurrence
Malware & files

The file, its nature and its network source

A native multi-rule engine combines ClamAV and external adapters to connect compromised artefacts to attackers.

  • Named webshell matched against a real file
  • Scan, quarantine and source-IP blocking
  • Injected-file versus modified-original distinction
  • Recovery only from a known-clean backup
06

Guardrails that make automation defensible

Intelligent mail scanning

Qualification adapted to legitimate messaging flows.

Local address reputation

Known-good addresses are reconciled automatically.

Advisory intelligence

External feeds corroborate; they never trigger a block alone.

Protected payments and webhooks

Static exemptions and poison-resistant dynamic learning.

249 governable countries

Geo-blocking is off by default and trusted networks remain untouchable.

Explicit network surface

Approved ports are centralised and audited in WHM.

Native WHM interface

Readable security, without leaving WHM.

Activity, decisions, web protection, health and network exposure come together in an interface made for server administrators.

Evidence-led remediation

Clean up without restoring the compromise.

YOORguard distinguishes an injected file from a modified legitimate file, then chooses a safe action using available backups.

Recovery connected to your backupsJetBackup · YOORbackup
01

Injected file

A webshell absent from the legitimate application is removed or quarantined.

Quarantine
02

Modified original

A clean version strictly older than the infection is restored through JetBackup or YOORbackup.

Clean restore
03

No clean version

The case is reported. YOORguard never restores a questionable backup at random.

Report
Autonomous by design

On the server. Under your control.

YOORguard runs as a Python daemon supervised by systemd, on the standard EasyApache4/cPanel stack and with no mandatory cloud dependency.

PythonAutonomous daemon
systemdHardened service
cPanelEasyApache4
0Cloud required
Frequently asked questions

Understanding YOORguard.

01Is YOORguard really integrated with cPanel?

Yes. Administrators control security from WHM and every customer gets a cPanel view strictly scoped to their account, including activity, attackers and quarantine.

02Can an address be blocked on external reputation alone?

No. Threat intelligence feeds remain advisory. An automatic firewall write requires hostile evidence observed locally.

03What is the difference between Observation and Enforce?

Observation analyses and decides without writing to the firewall. Enforce applies qualified decisions to nftables with a version-bound approval token.

04How does YOORguard avoid blocking legitimate visitors?

Ambiguous web traffic receives a signed challenge first. Trusted networks, server addresses, allow lists, payments and webhooks benefit from protected exemptions.

05What happens when a file is compromised?

An injected file is quarantined. A modified original can be restored from an older clean backup. With no safe version, YOORguard reports instead of taking a risk.

06What role does artificial intelligence play in YOORguard?

AI correlates and contextualises signals from web, network, identities, services and files. It produces an explainable scenario, while action remains subject to local evidence and deterministic guardrails.

Plans & partners

Protect, host and run your business.

Three YOORhosting NVMe SSD infrastructures to deploy YOORguard, followed by two selected partners that simplify business operations.

YOORhosting infrastructureNVMe SSD · Europe & Canada
Web hosting

Web NVMe SSD

A fast, manageable cPanel foundation for websites, blogs and shops.

From€7.95ex. VAT / month
  • Complete cPanel administration
  • Free SSL and HTTP/2
  • External daily backups
  • Expert support 24/7/365
Discover the plan
VPS hosting

VPS NVMe SSD

Full server control for a security configuration tailored to your needs.

From€7.95ex. VAT / month
  • Full administrator access
  • NVMe SSD performance
  • Configuration adapted to your load
  • Expert support included
Discover the plan
100% NVMe SSD24/7/365 support99.95% SLADaily backups
Business partners

A better-organised business around your infrastructure.

YOOR referral links. Terms, pricing and availability remain those of each partner.

QontoBusiness account

The business account designed for freelancers and companies.

Bring payments, cards, expenses and receipts together in one clear web and mobile interface.

  • Online opening and management
  • Expense tracking tools
  • Accounting exports and integrations
Discover Qonto
DougsOnline accounting

Your accounts, invoices and deadlines in one place.

Track your business and work with a chartered-accounting team from one interface.

  • Management dashboard
  • Accounts and declarations
  • Dedicated guidance
Discover Dougs
A different way to secure cPanel hosting

Local evidence before action.

Discover autonomous server protection that is clear in WHM and useful inside every customer’s cPanel space.