10 years of helping businesses, organizations and entrepreneurs build, run and protect their digital operations. Explore Services

close
Emergency

Armor SOS

Hacked, defaced, blacklisted, or quietly serving gambling pages into Google under your domain name? Message us now. We contain it today, clean it out, find the way in, and shut it.

Emergency

What’s probably happening right now

Before you call anyone: don’t delete files, don’t restore an old backup, and don’t change passwords yet. Deleting destroys the evidence of how they got in, and restoring a backup usually restores the backdoor along with it. Leave it exactly as it is and message us.

We clean these up across our own fleet every week, so nothing you’re about to describe will surprise us:

01 Gambling pages in your search results
Hundreds of pages you never made, indexed under your domain, invisible when you visit the site normally. We've cleaned this exact pattern repeatedly this year.
02 Your mail is being blocked everywhere
Your server ended up on a blacklist because one account is sending phishing. Now nobody receives your invoices.
03 The site is defaced or just gone
A message from someone claiming credit, or a blank page. Either way your clients are seeing it before you are.
What we do, in order
Everything below is included at one price. No setup fee, no per-incident invoice, no surprise line items.
Contain first - cut the attacker's access before anything elsehour one
Preserve the logs before they roll over and the evidence is gonehour one
Remove injected pages, shells and backdoors; all of them, not the obvious onesday one
Reset every credential the attacker could have takenday one
Get you delisted from Google Safe Browsing and mail blacklistsday one to three
Written report: what happened, how they got in, what we changedon completion
Hardening so the same route closes permanentlyon completion
A follow-up scan two weeks later, at no chargetwo weeks later
Included at no charge on Armor Shieldevery time
It costs less than buying it direct
Emergency incident work is normally billed by the hour, negotiated while your site is down, and capped at whatever you'll agree to at 11pm.
What you wantDirect priceTremhost
Emergency cleanup, one-offhourly, negotiated in a crisisquoted after free triage
Same site, on Armor Shield—$0, every time
Written incident reportusually extraincluded
Follow-up scanrarely offeredincluded
Hardening so it doesn't recurseparate engagementincluded
Free on ShieldAt $29 a month, Shield costs less than a single cleanup, which is why most clients who call us once end up on it afterwards.
Cloudflare list prices from cloudflare.com/plans. We are a Cloudflare partner and buy at wholesale across thousands of accounts, that is the whole reason we can charge less than you would pay going direct.

FAQ

Questions people actually ask

1. How fast can you start?
Triage same day, usually within the hour on the WhatsApp line. Containment - cutting the attacker off - is normally done the day you call us.
2. Will I lose my website?
Almost never. We clean in place wherever possible and take a forensic copy before we touch anything, so nothing is lost even if we have to roll back.
3. Do you work on sites hosted elsewhere?
Yes. Most SOS calls are for sites we don't host. We need access, not ownership.
4. I'm a developer and my client's site is hit. Will you deal with them directly?
Only if you ask us to. We work behind you, report to you, and never contact your client. Plenty of Zimbabwean developers use us exactly this way.
5. How much does it cost?
It depends on what we find, which is why triage is free — we'd rather look first than quote blind. A single infected WordPress site is a different job from a root-compromised server. On Armor Shield it's included at no charge.
6. How do I stop it happening again?
The report tells you exactly how they got in, and we harden that route as part of the job. The honest long-term answer is Shield, where the cleanup is included and somebody is watching between incidents.