SITECRAFT.IE
Eamon O'Leary
We completely re-engineered eamonoleary.ie, upgrading it to a high-performance, mobile-first architecture. This included a bespoke, responsive UI overhaul and implementing our zero-trust post-quantum security baseline to ensure their online presence is future-proof, extremely fast, and highly secure against emerging threats.
How We Actually Keep Your Site Safe
Real protections, running live. Here is exactly what is active on our server right now.
Most agencies say they take security seriously. We can show you the proof. Every tool in this table is live and active on our server right now — not a marketing claim. Each one is explained with a plain-English analogy, and linked to the peer-reviewed research that proves why it works.
| Security Layer | Plain English — What It Actually Does | Peer-Reviewed Proof |
|---|---|---|
| Ubuntu 24.04 LTS Operating System |
Think of the OS as the building your website lives in. Ubuntu LTS is a reinforced concrete structure with a five-year maintenance guarantee — patched, updated, and hardened automatically. No wood frames, no shortcuts. | View Study |
| OpenSSL 3.4.1 + TLS 1.3 Encryption Engine [Active] |
Like sealing every letter in a bank-grade envelope before it leaves the building. TLS 1.3 scrambles all data in transit so that even if intercepted, it is pure noise. All older, weaker protocols are completely disabled — no fallback, no exceptions. | View Study |
| ML-KEM (Kyber) PQC Quantum-Safe Keys [Active] |
Future quantum computers will crack today's standard encryption — like a master key that opens every lock in the building. ML-KEM uses mathematical problems even quantum computers cannot solve, future-proofing every connection for decades. This is the NIST-standardised solution (FIPS 203). | View Study |
| OpenSSH 9.9 — Key-Only Admin Access [Active] |
Our server cannot be accessed with a password at all. Entry requires a physical cryptographic key file — like needing the original physical key to a safe, not just knowing the combination. Password login is completely disabled at the configuration level. There is no door to guess at. | View Study |
| Fail2Ban — 5 Active Jails Brute Force Shield [Active] |
A door that locks itself after three wrong keycode attempts — and ejects the person permanently. Fail2Ban monitors SSH, web, mail, and admin logins across five simultaneous jails. Any IP showing suspicious behaviour is banned at the firewall level automatically, within seconds. | View Study |
| ModSecurity WAF Web App Firewall [Active] |
A security guard at the front door who checks every visitor's bag before they enter. If a request contains a weapon — SQL injection, cross-site scripts, path traversal — it is turned away before it ever touches the application. Every single HTTP request is read, every second. | View Study |
| CrowdSec Community IPS Collective Defence [Active] |
Every security guard on every street sharing a radio. When one building spots a troublemaker, every building on the network blocks them instantly. CrowdSec is a global threat intelligence network — our server gets real-time blocklists from millions of attack reports worldwide, before those attackers even try to reach us. | View Study |
| Lynis — CIS Benchmark Security Auditor [Active] |
A certified fire-safety inspector who walks every room of the building, checks every bolt and lock, then hands us a scored hardening report. Lynis audits our server against the CIS Benchmark — one of the most respected security standards in the world — and tells us exactly what to fix next. | View Study |
| AppArmor App Containment [Active] |
Like giving each staff member a keycard that only opens the specific rooms they genuinely need. AppArmor confines every application to a strict profile. If any process is compromised, it cannot reach files outside its boundary. The damage is contained to a single room, not the whole building. | View Study |
| UFW — Default Deny Network Firewall [Active] |
The building's default answer to anyone knocking on an unrecognised door is: no entry. UFW blocks all traffic by default and only allows specific, necessary ports. Every other connection is silently dropped — like a building with no public entrance except one staffed, ID-checked reception desk. | View Study |
| Audit Daemon (auditd) Tamper-Proof Log [Active] |
A tamper-resistant logbook bolted to the wall. Every admin command, every file change, every login attempt is recorded with a precise timestamp. If anything ever changes on the server — even a single configuration line — we know exactly what changed, when, and who did it. | View Study |
| Unattended Upgrades Auto-Patching [Active] |
A locksmith who automatically upgrades your locks the moment stronger ones exist — while you are asleep. Critical OS and package security patches are applied automatically, without waiting for a maintenance window. Vulnerabilities are closed before attackers can exploit them. | View Study |
| Rootkit Hunter (rkhunter) Integrity Scanner [Active] |
A security officer who memorises every brick in the building and checks daily that none have been secretly swapped. rkhunter scans every system binary and config file for signs of tampering. If anything has been secretly modified, it alerts us immediately — before any damage spreads. | View Study |
| HSTS + Security Headers Browser Protection [Active] |
Your browser makes a binding contract with our server: it will only ever connect over HTTPS, no matter what any third party says. Combined with content security and frame-protection headers, this eliminates entire categories of browser-based attacks — like telling every visitor to only ever use the secure, CCTV-monitored entrance. | View Study |
| Let's Encrypt SSL SSL Certificate [Auto-Renewing] |
Like a building that automatically renews its fire-safety certificate before it expires — no manual action, no lapses. Trusted SSL certificates are issued and renewed automatically every 90 days. Your visitors see the padlock. We see verified cryptographic identity. It never expires unnoticed. | View Study |
| Fail2Ban IDS Intrusion Prevention |
Like automated guard dogs that permanently ban any IP address that knocks on the door incorrectly more than three times, ensuring that brute-force attackers are exiled instantly without human intervention. | View Study |
| UFW Kernel Firewall Kernel Isolation |
Like an impenetrable concrete wall where only specific, heavily-guarded doors are allowed to exist at the operating system kernel level, completely isolating the core components from any external network traffic. | View Study |
| AIDE FIM Integrity Monitor |
Like a museum laser alarm system that triggers instantly if a critical system file is modified by even a single byte, giving us an unalterable forensic trail of any unauthorized changes on the filesystem. | View Study |
| OVH Hardware Isoltation Hardware Isolation |
Like building your house on a suspended magnetic platform so that earthquakes in a neighbor's yard cannot physically reach you, ensuring noisy neighbors or hardware failures on other instances never degrade your performance. | View Study |
| Rate Limiting & DDoS Mitigation Traffic Limiter |
Like a strict bouncer that instantly and physically removes entities if they try to speak too fast or artificially overcrowd the network lobby, keeping the pathways clear for genuine, legitimate visitors to interact smoothly. | View Study |
Custom Website Design & Secure Web Hosting Dublin
SiteCraft builds fast, modern websites for Dublin businesses — and we keep them genuinely secure. Whether you need a company website, an online shop, or IT support, we handle the technical side properly. That means real security, not just a padlock icon. We run our own hardened server infrastructure with enterprise-grade protections that most agencies three times our size don't have. You focus on your business. We make sure your website is fast, safe, and working.
What We Do
Professional, reliable, and secure web solutions for independent professionals and businesses in Dublin.
Websites
We design and build fast, beautiful, and reliable custom websites tailored to your business goals. From clean layouts to responsive designs that look perfect on phones and laptops, we ensure your website is easy to use, loads instantly, and provides a smooth experience for your customers.
E-Commerce
We build user-friendly online stores and secure shopping carts that make selling simple and safe. We set up reliable checkout systems, protect customer payment information, and guard your business from fraud, so you and your customers can transact with absolute confidence.
IT Consultancy
We help you choose the right technology for your business and plan for long-term success. From reviewing your current software to setting up secure remote work systems, our friendly IT consulting services in Dublin ensure your technology works for you, not against you.
Infrastructure Security
We keep your business emails, domain name, and files safe from unauthorized access. By setting up reliable backup plans, secure passwords, and active spam filters, we make sure your critical business data remains secure and fully under your control.
Security Training
We teach your team how to recognize online risks in a clear, straightforward way. Our friendly security awareness training helps your employees spot phishing emails, use safe login habits, and protect your business data during their daily tasks.
What Our Clients Get
Concrete outcomes from our 20-layer security infrastructure — explained plainly.
- Absolute Data Confidentiality: Your database records, transaction logs, and customer information are protected through isolated user accounts and strict system environments. Your data is completely separated and invisible to anyone else on the server.
- Optimised Speed & Reliability: Modern server configurations and smart caching keep page load times under a second, even during traffic surges. Fast for your visitors, efficient for you.
- Active Threat Protection: Multi-layered security actively monitors all traffic. Firewalls and scanners detect and block malicious attempts instantly — without affecting real users or slowing your site.
- GDPR & Compliance Ready: Encryption, secure coding standards, and detailed access logging make it straightforward for your platform to pass compliance reviews and security audits.
Get in Touch
Initiate a technical consultation with our team. We guarantee a response within one business day.
Secure Communication
We maintain secure communication channels to guarantee client confidentiality and protect sensitive project details.
To schedule a web review, discuss a custom software project, or enquire about consulting services, please use the secure contact form here or reach out directly using the links above.
All client communication and email exchanges are handled with industry-standard encryption protocols.