HardStacked

Reversible Linux hardening

Secured Protected
Reversible

Out of the box, a fresh Debian or Ubuntu server is wide open — password login on, no brute-force protection, nothing locked down. That's why bots find it and start breaking in within minutes. HardVps closes every door — SSH, passwords, kernel, network — one reviewable fix at a time, and every one of them undoes with a single command.

Ubuntu 24.04 tested  ·  Debian & Ubuntu  ·  x86_64 + ARM64  ·  no agent, no telemetry

ubuntu-vps — ssh

Why not a script?

Not another hardening script.

Free hardening scripts are everywhere. They don't carry the same risk. A script applies everything at once and leaves you to find out what broke — on a machine you may only reach through SSH. HardVps shows you each change before it runs, applies only what you approved, and sets the original aside so you can put it back byte for byte.

The usual hardening script HardVps
Dumps 40 changes on your box at once Applies only the fixes you approved, one at a time
Rollback plan: reinstall the server Byte-exact revert, SHA-256 verified — weeks later if you want
No safety net if a fix cuts off your own SSH access Stops before any fix that touches your access — and refuses to arm if no port is listening
Claims a score it measured on someone else's machine Measures before/after with Lynis on your box
Silently “applies” things your distro already does Nothing runs before you've seen the exact command

The threat

Your server went online. The bots found it before you finished setting it up.

Automated scanners sweep the entire internet, around the clock. A newly exposed service gets its first probes within minutes. Attackers even start scanning for a new vulnerability a median of 15 minutes after it's published. Nobody chose you. They're testing every door on the street, and default configs are the ones that open.

Your CPU starts mining for someone else

The dominant payloads dropped on cracked SSH servers: crypto-miners and self-spreading botnet worms. Your bill, their coins.

Your secrets walk out the door

SSH keys, .env files, database dumps — then every machine and account that server could reach. One weak box compromises the rest.

Your provider pulls the plug

Abuse reports land, the account gets suspended, the IP blacklisted. The cleanup and migration? That's your weekend.

sources: Palo Alto Networks Unit 42 (attack-surface scan study) · AhnLab ASEC honeypot reports, 2025

How it works

Three steps. Zero expertise required.

See it first

Before anything touches your server, HardVps shows you what will change — in plain words, with the exact command it will run. Nothing happens without your OK.

$ hardctl preview SSH-7408-pw sshd drop-in: PasswordAuthentication no

Protect

Check the boxes you want — HardVps does the rest. Before each change, the original is set aside in a safe place. Automatically, every single time.

$ sudo hardctl apply DEB-0880 original captured · fail2ban active

Change your mind, anytime

Undo one change — or all of them. Your server comes back exactly as it was, proof included. No snapshot, no reinstall, no sweat.

$ sudo hardctl revert DEB-0880 restored · SHA-256 verified

Proof

Numbers from a real VPS. Not a lab, not a landing page.

Fresh Ubuntu 24.04 cloud instance, Lynis pinned at 3.1.7. Full cycle, measured:

What's this score?

Lynis is a widely used open-source security auditor. It inspects a Linux box and rates its hardening from 0 to 100 — the same yardstick sysadmins use. In our tests, an unhardened Debian/Ubuntu server measured 57. The point isn't the number itself: it's that it's measured on your machine, before and after — by a tool we don't control.

State Lynis hardening index
Baseline — untouched server 57
After applying the MEDIUM tier (32 fixes) 79
After reverting every fix 57

measured 2026-07 · Ubuntu 24.04 LTS x86_64 · Lynis 3.1.7 · same box, same day

The honest part

A deeper tier barely moves the score — and we say so. Tiers buy you deeper hardening (key-only SSH, stricter auth), not vanity points. Every fix shows you the exact command before it runs, so you can judge for yourself whether your box needs it.

  • Revert without apply — clean no-op, exits 0, changes nothing.
  • Double apply — the second run never overwrites the captured original. Restore stays byte-exact.
  • Two fixes, one file, reverted out of order — file comes back SHA-256 identical. Backups are captured per file, not per action.
  • File that didn't exist before — revert deletes it, not just empties it.
  • Aggressive fixes too — /tmp remounted without noexec, SSH still up after reverting key-only auth. No lock-out in the whole cycle.

What's inside

What each fix actually stops. In plain words.

Thirty-two curated fixes — each one opt-in, each one undoable, each one tied to a real attack, not an abstract checkbox. A sample:

SSH-7408-pwSSH key-only authentication

Stops: the password-guessing bots from your auth.log — all of them. No password to guess.

MEDIUM
DEB-0880fail2ban

Stops: brute-force floods — repeat offenders get banned at the firewall, automatically.

SAFE
KRNL-6000Kernel sysctl hardening

Stops: spoofing and redirect tricks at the network layer — the plumbing bots poke first.

SAFE
AUTH-9262Password quality policy

Stops: “admin123” from ever existing on this box. Weak passwords are how dictionaries win.

MEDIUM
AUTH-9328Default umask 027

Stops: an intruder who lands in one account from reading every other user's files.

SAFE
STRG-NICHERare protocol blacklist

Closes: network protocols you've never used — but exploit kits have. If you don't need the door, brick it.

MEDIUM
BANN-7126Legal login banners

Required by most compliance checklists.

SAFE
ACCT-9622Process accounting

For: the morning after. Who ran what, when — an audit trail that survives an incident.

SAFE

+ 24 more — sysctl sets, login.defs, core dumps, compiler perms, firewall, auditd…

Pricing

One license. Your server, hardened — reversibly.

HardVps · medium

$39 $19.99 one-time · USD

◆ Special price

  • 32 curated fixes — SSH, PAM, kernel, network, firewall, accounting
  • Preview → apply → revert on every single fix
  • Byte-exact rollback, SHA-256 verified, reboot-proof backups
  • Lynis before/after report — pinned 3.1.7, measured on your box
  • Tested on Ubuntu 24.04 (x86_64) · Debian 12/13, Ubuntu 22.04, ARM64 not covered

USD/CAD/EUR handled at checkout · VAT/GST included where it applies
Read the license and refund policy before buying

Buy · via Lemon Squeezy

custom hardened image

on request
  • Hardened from install — partition layout, boot chain
  • Higher ceiling than any live-system tool can reach
  • Built and measured against your workload
Ask about it

HardPinext up

in the works
  • Same engine — already runs on ARM64, zero porting
  • Pi-tuned tier: SD-card wear, GPIO/camera-friendly defaults
  • Your homelab deserves the same rigor as a datacenter

audit-pi free · open source

Our security audit for Raspberry Pi. One scan, one readable report — see where yours stands before spending a dollar.

Start free with audit-pi

Rather have an expert do it, or rescue a server that's already in trouble?

Hands-on hardening, debloat and rescue on your live server, under the HardStacked name. Guided or supervised access, time-boxed and logged.

$49/h · USD
Book a session
audit-pi — free

Our free Raspberry Pi security audit. See where your Pi stands before spending a dollar.

github.com/Hardstacked/audit-pi →

FAQ

The questions you should be asking.

Can it lock me out of SSH?
The only fix that could — key-only authentication — is opt-in, clearly flagged, and requires explicit confirmation. And because every change is reversible, your provider's rescue console can always run hardctl revert SSH-7408-pw and restore the original config, verified by SHA-256. In our full test cycle on a live VPS, SSH stayed up through apply and revert.
What does “byte-exact” actually mean?
Before HardVps touches any file, it captures the original — once, before the first change, in a backup that survives reboots. Revert restores that capture and compares SHA-256 checksums — if the restored file doesn't match the backup, the revert fails loudly instead of claiming success. Files that didn't exist before are deleted, not emptied. Packages that weren't installed are removed. If it was there before, it's there after — identical.
Which systems does it support?
Tested and supported on Ubuntu 24.04 LTS (x86_64) — that's where every number on this page was measured. The same code runs on Debian 12/13, Ubuntu 22.04 and ARM64, and we expect it to work there; those aren't covered by support, and we say so rather than pretend otherwise.
Does it phone home?
No. No telemetry, no account, no license server. HardVps talks to your package mirror when a fix installs a package — that's it. A security tool that spies on you isn't one.
Why doesn't a deeper tier raise the score more?
Because Lynis' index saturates: the measured gap between the base tier and the deepest one is a couple of points. Tools that promise “+30 points per tier” are selling you the scoreboard, not security. Deeper tiers buy stricter authentication and a smaller attack surface — we show you what each fix does instead of inflating a number.