HOSTING / A BETTER BUYING CONVERSATION
Before You Buy Hosting
Write down the job, the limits and the responsibilities before comparing prices. This checklist helps you ask for an answer that can be tested—not just a reassuring adjective.
1. Describe the Work You Need Done
List the website or application, expected users, mailbox count, storage, business hours and required software. Separate launch needs from future possibilities. A simple published site does not automatically need a VPS; custom server software may not fit a website builder.
- What must run, and which versions or integrations are required?
- How much capacity is used now, and how fast is it growing?
- What does a busy hour look like—not only an average month?
- Who is available to maintain it?
2. Put Responsibilities in Writing
Assign an owner for account access, DNS, operating-system patches, application updates, monitoring, backup checks and restores. Ask what “managed” includes when something goes wrong, not just while everything works.
“24/7 support” might describe when a ticket can be opened. Clarify when a qualified person responds, what they investigate and whether hands-on work costs extra.
3. Calculate the Commitment, Not the Introductory Price
Compare the full period you expect to use. Include setup, renewal, licenses, backup storage, support, excess use and migration. A price shown “per month” may require payment for a year or more up front. Read cancellation and refund terms before treating it as a monthly commitment.
Decode consumption, overages and “unlimited” →
4. Read the Limits Beside the Promises
Ask about CPU, storage, file count, mail sending, database connections, network rate and concurrency where relevant. A large storage number does not compensate for a workload that exceeds the CPU limit. Confirm what is shared across sites or users.
A free tier can have eligibility rules, expiration, usage caps or automatic paid overages. Confirm whether payment details are required, how billing starts and how to stop it.
5. Define Recovery Before an Outage
- Recovery point objective (RPO): how much recent data loss can be tolerated?
- Recovery time objective (RTO): how quickly must service return?
- Restore test: has someone recovered usable data into a separate environment?
- Independence: can one account failure, deletion or compromise remove both production and backup?
Availability percentages are measured under a contract’s rules. For context, 0.1% of a 30-day month is 43.2 minutes. That arithmetic does not tell you which incidents an SLA excludes, how claims work, or when the application will actually recover.
6. Check Security, Privacy and Data Location
Ask about MFA, individual administrator access, supported updates, encryption and recovery access. Confirm where production data, backups and logs are processed when location matters to your organization. A provider’s certification does not automatically make your own application compliant.
HTTPS protects the connection; it does not prove a hosting plan includes secure application configuration or reliable backups. The certificate workshop explains that distinction.
Security controls and privacy practices are related, but not interchangeable. Ask what information is collected, who can access or decrypt it, whether it is used beyond delivering the service, and when logs and backups are removed. Use the hosting privacy checklist →
7. Plan the Exit
Verify that you control the domain and can export the website, database, mail and files in usable formats. Builder templates, application runtimes, database features or proprietary APIs can complicate a move. Ask about data-retrieval fees and the deadline before cancelled-service data is removed.
For migrations, inventory DNS and mail records, test the new service, keep a recovery route and allow an overlap period. Moving nameservers, website files and mailboxes are separate operations.