Guides · The Promptable Sites team · Updated October 2026

Is a Site You Own as Safe as Squarespace?

Short answer: Yes, if it’s set up well. Squarespace is secure, and a site you own as plain files can be just as safe: there’s no login page, database, or plugins on the site for anyone to break into. What changes is where the risk lives. It moves to your accounts, so two-step sign-in on each one matters more than anything else.

Squarespace is secure

Squarespace handles security for you. Every site gets a free SSL certificate (the padlock in the browser), checkout pages meet the card industry’s security standard, and login passwords are always encrypted.1 If security is your main worry, that’s a fair reason to like Squarespace.

How most websites actually get attacked

Most website break-ins come through the parts of a site that run code on a server: login pages, databases, and add-ons. WordPress shows this clearly. In 2025, security researchers found 11,334 new security holes in WordPress plugins, themes, and core, and 91% of them were in plugins. Only 6 were in WordPress itself.2

Why a site of plain files is hard to break into

A site you own, built the way we build them, is a set of plain files: pages, styles, and images. There’s:

The files are served by Cloudflare, which includes on its free plan:

Where the risk moves: your accounts

On a site you own, the keys are yours. That’s the point, and it’s also the responsibility. Anyone who gets into these accounts could change your site:

Account What it controls
Your domain company Where your website and email point
GitHub Your site’s files
Cloudflare Your hosting and domain settings
Claude, through the email or Google account you sign in with The tool that edits your site

Turn on two-step sign-in for every one that offers it. It’s the single most important step. A stolen password alone then isn’t enough. Claude signs you in through your email or Google account, so protect that account with two-step sign-in.7

Also:

Don’t forget email security

Your domain also proves your email is really from you, using settings called SPF, DKIM, and DMARC. Some domains are missing one or more of these, which makes it easier for someone to send fake email that looks like it came from you. A move is a good time to check and fix them.

What we do on every move

We set this up with you. On every move, we:

Questions owners ask

Can my site get hacked if it’s just files? Nothing is ever impossible to attack. But with no login page, database, or plugins on the site, the usual ways in aren’t there. The bigger risk is someone getting into one of your accounts, which is why two-step sign-in matters.

What if Claude makes a bad change? Every version of your site is saved in GitHub, so you can go back. Sites we move also come with rules for Claude and a preview before anything goes live.

Who fixes security problems after the move? Plain files need very little upkeep. Cloudflare keeps its own systems updated. Your job is to keep your accounts protected.

Do I need a security plugin? No. There are no plugins on a site of plain files.

Sources

Footnotes

  1. Squarespace Help Center, Squarespace and SSL. ↩

  2. Patchstack, State of WordPress Security in 2026. ↩

  3. Cloudflare Docs, Universal SSL. ↩

  4. Cloudflare Docs, DDoS Protection. ↩

  5. Cloudflare Docs, Turnstile. ↩

  6. Cloudflare Docs, Turnstile plans. ↩

  7. Claude Help Center, Logging in to your Claude account. ↩