Infrastructure, explained

What keeps a site fast and safe after launch.

The Infrastructure part of every project covers three things. This page explains what each one is, what it protects you from, and how you can check it yourself.

01 · CDN & caching

Closer to the visitor, less to download.

A CDN (content delivery network) keeps copies of your site on servers around the world, so each visitor is served from one nearby instead of from a single data centre far away.

Caching tells browsers and servers which files they can reuse instead of fetching again. Together they cut the time before your page appears, and they keep the site up when traffic spikes.

  • CDNServes from nearby. Your files are copied to edge servers in many cities. A visitor in Lisbon and one in Tbilisi both get a short trip.Cloudflare, Bunny, Fastly
  • Cache-ControlReuses what hasn't changed. Images, fonts and scripts are stored in the browser, so returning visitors don't download them again.public, max-age=31536000, immutable
  • CompressionSends smaller files. Text files such as HTML, CSS and JavaScript are compressed before they travel and unpacked by the browser.Content-Encoding: br
  • Image formatsRight size, modern format. Images are served as AVIF or WebP at the size each screen needs, and off-screen images load only when scrolled to.srcset · loading="lazy"
02 · Security headers & TLS

Security headers: the part nobody sees.

Every time your site loads, the server sends a set of instructions to the browser along with the page. Security headers are the instructions that tell the browser what to block.

They cost nothing to add, and most websites still don't have them. Without them, your visitors are more exposed to injected scripts, clickjacking and data leaks. We configure them on every site we ship.

TLS is the encryption behind the padlock in the address bar. We set it up with a current version (TLS 1.2 or 1.3), renew certificates automatically and switch off outdated ciphers, so traffic between visitors and your site can't be read or altered.

  • Strict-Transport-SecurityForces HTTPS. Stops the browser from ever loading your site over an unencrypted connection, where traffic can be read or altered.max-age=63072000; includeSubDomains; preload
  • Content-Security-PolicyControls what can run. Lists which scripts, styles and images are allowed, so injected code (XSS) is refused by the browser.default-src 'self'; script-src 'self'; frame-ancestors 'none'
  • X-Frame-OptionsBlocks clickjacking. Stops other sites from embedding yours in a hidden frame to trick visitors into clicking.DENY
  • X-Content-Type-OptionsStops file-type guessing. Prevents the browser from treating an uploaded file as a script.nosniff
  • Referrer-PolicyProtects private URLs. Limits how much of your page address is passed on when visitors follow a link to another site.strict-origin-when-cross-origin
  • Permissions-PolicySwitches off what you don't use. Disables camera, microphone and location access unless the site needs them.camera=(), microphone=(), geolocation=()
Website report

Find out what's really slowing your site down.

We test your site's speed, security headers and server configuration, then send you a written report. Every issue comes with evidence: raw headers, screenshots, scores and links to the tests we ran, so you or any developer can verify it.

  1. Speed and Core Web VitalsMeasured page by page, on mobile and desktop.
  2. Security headers, TLS and cookiesWhat's set, what's missing and what's misconfigured.
  3. Proof for every findingRaw headers, screenshots and links to every test we ran.
  4. Prioritised fixesWhat to fix first, and what each fix involves.
  5. Plain languageWritten so you can act on it, even if you don't code.
03 · Monitoring & support

Problems found before your visitors find them.

A site that was fast and secure at launch can slow down or break later: a plugin update, a traffic spike, an expired certificate. Monitoring watches for these automatically and alerts us when something changes.

Support means someone is responsible for acting on those alerts, keeping software up to date and restoring the site if anything goes wrong.

  • Uptime checksKnows when the site is down. The site is requested every minute from several regions. If it stops answering, we're alerted.HTTP check · every 60 s
  • Real-user performanceCatches slowdowns. Core Web Vitals are measured from real visitors, so a change that makes the site slower shows up straight away.LCP · INP · CLS
  • Error trackingSees what breaks. Errors in the browser and on the server are logged with the page, browser and steps that caused them.Stack trace · browser · URL
  • Certificate & domain expiryNo surprise outages. We're warned well before a TLS certificate or domain registration runs out.Alert 30 days ahead
  • Updates & backupsStays patched, can be restored. Software and dependencies are kept up to date, and backups are taken on a schedule and test-restored.Daily backups · tested restores