“Which plan do I need?” is a fair question to ask before committing to anything, and most pricing pages don’t actually answer it — they just list features and expect you to self-sort. Here’s a direct comparison of Tremhost Armor Lite, Pro, and Business, organized around the actual question that matters: what kind of site do you run, and what’s actually at risk if something goes wrong?
The Three Tiers, Side by Side
| Feature | Armor Lite | Armor Pro | Armor Business |
|---|---|---|---|
| Price | $35/month ($30 setup) | $3,540/year | See plan details |
| DNS/CNAME setup | Included | Included | Included |
| Universal SSL, Full (Strict) | Included | Included | Included |
| Proxy (hides origin IP) | Included | Included | Included |
| Baseline firewall (bad bots, XML-RPC, login endpoints) | Included | Included | Included |
| Unmetered DDoS protection | Included | Included | Included |
| Full managed WAF ruleset, false-positive tuned | — | Included | Included |
| Custom WAF rules for your application | — | Included | Expanded capacity |
| Rate limiting on login/checkout | — | Included | Included |
| Image optimization | — | Included | Included |
| Automatic Platform Optimization (WordPress) | — | Included | Included |
| Monthly security & traffic report | — | Included | Included |
| PCI DSS-ready configuration guidance | — | — | Included |
| Prioritized support escalation | — | — | Included |
| Quarterly configuration review | — | — | Included |
Armor Lite: The Baseline Everyone Should Have
Who it’s for: a personal site, a small brochure-style business site, a blog, or any site where the main risk is “basic bad traffic” rather than a targeted, sustained attack.
Lite covers the fundamentals that genuinely matter for almost any website: your origin IP is hidden, SSL is properly configured rather than left on a weaker default, and baseline rules catch the most common abuse patterns — bad bots, XML-RPC abuse, login endpoint probing. Unmetered DDoS protection means there’s no volume ceiling where the protection itself becomes the bottleneck.
What it doesn’t cover: anything requiring custom tuning for your specific application, rate limiting on sensitive endpoints like checkout, or ongoing visibility into what’s actually being attempted against your site.
Armor Pro: For Sites With Something to Actually Protect
Who it’s for: an active WordPress site, an online store, a membership site, or anything where login abuse, checkout fraud, or application-specific vulnerabilities are realistic risks — not just generic bot noise.
The jump from Lite to Pro is really the jump from “generic protection” to “protection tuned to your actual site.” A managed WAF ruleset tuned to avoid false positives means legitimate traffic doesn’t get blocked by accident — a common frustration with poorly configured firewalls. Custom WAF rules mean the protection reflects what your specific application actually does, not a one-size-fits-all template. Rate limiting on login and checkout endpoints directly addresses the two places most abuse concentrates. And the monthly report means you’re not just hoping it’s working — you can actually see what was blocked.
What it doesn’t cover: compliance-specific configuration or the kind of ongoing human review that comes with Business tier.
Armor Business: For Sites Handling Real Stakes
Who it’s for: ecommerce businesses processing payments, sites with regulatory or compliance obligations, or any business where downtime or a breach has a serious financial or reputational cost — and where “we’ll get to it” isn’t an acceptable response time.
Business tier isn’t just “more rules” — it’s expanded custom rule capacity for more complex applications, PCI DSS-ready configuration guidance for businesses handling payment data, prioritized support escalation (meaning you’re not in a general queue when something’s wrong), and quarterly configuration reviews, which matter because security configuration isn’t a “set once” task — what was correctly configured six months ago may not reflect how your site or traffic has changed since.
Worth being honest about: if you’re not handling payment data directly and don’t have compliance requirements, Business tier’s specific additions (PCI guidance, quarterly reviews) may be more than you actually need — Pro may be the better fit even for a fairly active site.
A Simple Way to Decide
Ask these in order:
- Does your site handle payment data directly, or have compliance requirements? → Business
- Does your site have logins, checkout, or a specific application worth protecting beyond basic hosting? → Pro
- Do you just need solid, unmetered baseline protection with your origin IP hidden? → Lite
What Happens If You Guess Wrong
Moving between tiers isn’t a one-way decision — a site that starts on Lite and grows into needing custom rules or rate limiting can move to Pro later, and the reverse is also reasonable if a Business-tier feature set turns out to be more than what’s actually needed. The honest approach is starting with what your site’s current risk profile calls for, not the most expensive tier “just in case.”



