Bright Cloud Studio Infrastructure & Cost Review August 2026 88 accounts / 3 servers Billed annually, Nov–Jan

We are spending more on
managing servers than on
the servers themselves.

Hosting brings in roughly $42,000 a year and costs about $20,700 to deliver. Over half of that cost is people, not machines — and most of the people cost traces back to one unsolved technical problem: nothing stops a single site from taking down everything next to it.

Annual revenue$41,998
Annual cost$20,728
Gross margin51%
Cost / account / mo$20.81
Unpriced risk Server management rests on Andy, Cloudflare rests on John. If either is unavailable, all 88 sites are exposed — and no line in this report captures it.

What we run today

Three servers, named for months

Each is an AWS Lightsail 2XLarge — 8 vCPU, 32 GB memory, 640 GB SSD, 7 TB transfer, at $164 a month. All three run cPanel/WHM and Imunify360, with per-site backups to Backblaze B2. Clients pay $33 a month plus $110 a year for SSL.

November
Lightsail 2XL · cPanel Premier
43 accounts
Paying sites43
Server cost / mo$258.74
Cost per account$6.02
Carrying its weight. Densest server, lowest unit cost.
October
Lightsail 2XL · cPanel Premier
35 accounts81%
Paying sites35
Server cost / mo$258.74
Cost per account$7.39
Healthy. Room for another 8 sites before anything changes.
September
Lightsail 2XL · cPanel Pro
1023%
Paying sites5 of 10
Server cost / mo$242.74
Cost per paying site$48.55
Held deliberately light. Heavy sites live here so they don't crowd the others — isolation bought with hardware, at 8× November's unit cost.

Meter fill compares account count against November, the fullest server. Server cost combines the Lightsail instance, its cPanel licence and Imunify360.

September is doing real work — just expensively

It's kept sparse on purpose: a handful of resource-hungry sites are spread across servers rather than stacked on one, so they don't starve their neighbours. That's a sound instinct, and it's the correct response to the tooling we have. But it means we're buying isolation in $164 increments of hardware, when per-site limits do the same job in software for $13–16 a month across the whole fleet.

Two more sites land on September before year end, taking it to 12 accounts and 7 paying. That tips it from a small monthly loss to roughly $52 a month positive — still at $34.68 per paying site against November's $6.02. The gap is what hardware-based isolation costs.

Where the money goes

Labour is 54% of the cost of operations

Licensing gets all the attention because the invoices arrive on a schedule. But cPanel is the fourth-largest line in the business. The two labour lines together are nearly five times bigger.

Lightsail $5,904 cPanel $2,328 Imunify + B2 $1,371 Andy — upgrades & emergencies $5,625 Security team — Imunify & Cloudflare $5,500

Infrastructure $9,603 (46%) · Labour $11,125 (54%) · Total $20,728

Line itemBasisMonthlyAnnual
Client fees83 paying sites × $33$2,739$32,868
SSL fees83 sites × $110/yr$761$9,130
Revenue$3,500$41,998
AWS Lightsail3 × 2XLarge @ $164$492$5,904
cPanel/WHM2 × Premier, 1 × Pro$194$2,328
Imunify3603 servers @ $24.75 — to retire$74$891
Backblaze B2actual billed rate — S3 target, portable$40$480
Andy — server upgrades$750 × 3.5 rounds$219$2,625
Andy — emergencies & generalmidpoint of range$250$3,000
Security teamImunify & Cloudflare rules$458$5,500
Total cost$1,727$20,728
Gross margin51%$1,773$21,270

Clients are invoiced annually, with bills going out between November and early January. Revenue is shown as a monthly average for comparison against costs, which are genuinely monthly. Labour lines use the midpoint of the ranges given.

What's actually wrong

Three cost problems, one root cause

Expensive fix

We isolate with hardware

$164/mo

Heavy sites get spread across servers so they don't crowd their neighbours. It works, but a whole instance is the most expensive unit of isolation available — software limits do the same job fleet-wide for a tenth of it.

Not working

Spreading sites isn't isolation

43 sites

Three servers exist partly to contain blast radius. But without per-site limits, one bot storm on November still takes down the other 42 sites with it. We're paying for a safety strategy that doesn't hold.

Rework

Security time is mostly cleanup

$5,500/yr

Storm hits, someone writes a blunt Cloudflare rule to stop it, the rule breaks normal site behaviour, someone unwinds it. That loop is a symptom of missing isolation, not security work — and Imunify, tuned for WordPress, is not catching enough to break the cycle.

The pattern worth naming

Every expensive line traces back to the same gap: no per-site resource ceiling. It drives the emergency callouts, it drives the Cloudflare rule churn, and it's why we spread heavy sites across whole servers instead of capping them individually. None of these are mistakes — they're the right moves given the tooling. But they're all workarounds for one missing capability, and fixing that capability is the only change that moves several lines at once.

Key-person risk

Our bus factor is one. Twice.

Every other problem in this report costs money. This one can stop the business. Splitting work between server management and security feels like redundancy, but each half still rests on one person — so the split shared the workload without sharing the risk. Imunify is the exception, and it shows what the rest should look like.

Andy Bus factor 1
Server management · deployment · Imunify

Only Andy can

  • Run the upgrade cycle across all servers
  • Respond to a server-down emergency
  • Build and provision a new server from scratch
  • Diagnose anything below the cPanel interface
If unavailable: no upgrades, no new client onboarding, and an outage lasts until we find and brief an outside contractor on infrastructure nobody has documented.
John Bus factor 1
Cloudflare security

Only John can

  • Write and unwind Cloudflare rules under pressure
  • Tell which of 88 zones has which custom configuration
  • Judge whether a traffic spike is an attack or a customer
  • Undo a rule that has broken a live site, quickly
If unavailable: bot storms get met with guesswork, and 88 zones of per-site tuning become undocumented state nobody can safely change. Nothing in this column is shared with anyone.
Malware & server security Covered — two people

Both Andy and the owner can run Imunify, so this is the one area where losing a person does not stop work. It shows the fix is not complicated: a second person who has actually done the task, not read about it. Imunify is being retired, so the point to carry forward is the arrangement rather than the tool — whatever replaces it gets set up by two people from day one. Everything above needs to look like this.

Why the migration is the moment to fix this

Right now the knowledge is tribal: it lives in two heads and in the accumulated hand-tuning of 88 Cloudflare zones and three hand-built servers. A platform change forces all of it into the open, because everything has to be rebuilt deliberately rather than remembered.

That cuts both ways. Done carelessly, migrating to Enhance increases the exposure — a new platform only Andy understands is worse than an old one only Andy understands. Done deliberately, with two people learning it side by side and a runbook written as we go, it is the cheapest chance we will get to fix this.

What actually reduces the exposure

Options

Four ways forward, priced

Each option is cumulative, and every row below folds September’s sites onto the remaining servers. Important ordering note: that consolidation is only safe after per-site limits are in place. Doing it first would put the heavy sites next to 35 unprotected neighbours — exactly the risk September exists to avoid.

Do nothing3 servers · cPanel
$20,728baseline
Consolidate only2 servers · no isolation
$17,190−$3,538
Add CloudLinux2 servers · cPanel + LVE
$15,574−$5,154
Replace cPanel with Enhance2 servers · containers · no Imunify
$11,718−$9,010
OptionInfraAndySecurityTotalMargin
Do nothing$9,603$5,625$5,500$20,72851%
Consolidate to 2 servers$6,690$5,000$5,500$17,19059%
+ CloudLinux LVE limits$7,074$4,000$4,500$15,57463%
+ Enhance, Imunify retired$4,968$2,750$4,000$11,71872%

What each option changes

Replacing Imunify

Imunify is $891 a year and, by our own experience, underperforms. A good part of why: its headline features — CMS core-file cleanup, vulnerability patching, the WordPress toolkit angle — are built around WordPress, Joomla and OpenCart. We run Contao. We are paying full price for a product whose best work does not apply to our stack.

Dropping it does not mean dropping protection. Two layers replace it, and between them they cover more than we have now:

The alternatives worth knowing about: cPGuard supports Enhance and cPanel both, so it is the option if we stay on cPanel; operators migrating from Imunify to it report finding genuine embedded backdoors that Imunify had missed for years, which matches our own sense that it is not catching much. BitNinja costs more and one operator who tested all three rated it highest, with per-website pricing available for Enhance hosts. Any of the three is a defensible pick; cPFence is the cheapest and the most tightly built for the platform.

What we gain and what we give up

Net saving is $785 a year on licensing, but that is the least interesting part. The real change is that malware containment stops depending on a scanner noticing something and starts being a property of how sites are run — each one in its own container, unable to reach its neighbours. Detection becomes the second line rather than the only one.

What we give up is a single WHM-integrated dashboard. cPFence runs its own web console rather than living inside the Enhance UI, so the team works in two places. Worth confirming during the pilot that this is acceptable day to day, because it is a workflow cost rather than a licensing one.

Candidate review

What Enhance actually gives us

Everything below is what the platform ships as standard, gathered in one place so the team can pick it apart. Treat it as a starting position rather than a decision — if someone has used a panel that does this better, that is worth more than anything in this document.

01 Isolation

A container per website
Every site runs in its own lightweight Linux container, even under the same subscription. This is the thing we are actually buying — malware cannot cross between sites and a storm cannot spill sideways.
Per-website resource caps
CPU, I/O bandwidth, IOPS, process count, swap, inodes and memory, each overridable per site. Heavy sites get bigger ceilings instead of their own server.
Move sites between servers on the fly
Relocate a site or swap its web server without reconfiguration, so rebalancing stops being a migration project.

02 Backups

Nightly incremental, included
Frequency, retention, initial delay and minimum backup age are all configurable. Deduplicated with filesystem hard links, so only changed files copy.
Backblaze keeps working
Targets a server inside the cluster or any S3-compatible provider. Our existing B2 destination carries over rather than being rebuilt.
Granular, self-service restores
A whole site, one file, a database or a mailbox. Clients can restore themselves from the panel, including sites they have deleted, which takes those requests off our desk.
Server loss recovery
Restore sites onto a different server in the cluster from the latest backup.

03 Security

ModSecurity with OWASP rules
Pre-configured across Apache, Nginx and LiteSpeed rather than hand-tuned per server.
Brute-force protection and 2FA
Built in, with optional TOTP that end users can turn on themselves.
Written in Rust
Rules out memory-safety bug classes at the compiler level. Not a feature we will ever notice working, which is the point.
cPFence covers scanning
$0.10/site/mo · ~$9/mo for the cluster
Real-time malware detection and cleanup, DDoS protection, abusive-IP blocklist. Runs on every role including mail and database-only servers.

04 Operations & cost

No per-server licence
$0.15/site/mo · ~$13/mo for all 88
One cluster licence covers unlimited servers. Staging sites, addon and alias domains, service domains and soft-deleted sites are never billed — so our five dev accounts likely cost nothing.
Single-command server deployment
New servers join the cluster and inherit global service settings automatically. This is the line that attacks Andy’s $500 setup fee and the $750 upgrade rounds.
cPanel importer
Pulls accounts over SSH or the WHM API with databases, mail and DNS intact.
Full REST API
Every function is scriptable, which is what makes fleet-wide changes repeatable instead of manual.
Client panels and email included
Client-facing accounts and mail hosting, no add-on licence.

05 What to push back on

It expects more sysadmin depth than cPanel
Consistently reported by practitioners. This is the main reason to run the pilot with two people and budget real ramp-up time.
Multi-server is the design assumption
Control panel, web, database and backup are separate roles. A single box is fine to evaluate, not to run production. No per-server fee makes this cheap, but it is more moving parts than three cPanel machines.
Cloudflare needs the panel IPs whitelisted
Inter-server traffic gets challenged otherwise, and we lock ourselves out of our own backend. Worth knowing before day one rather than during it.
S3 backup target is still beta
Run the native cluster backups alongside it and prove a Backblaze restore before relying on it.
cPFence lives outside the Enhance UI
Its own console, so the team works in two places. A workflow cost, not a licensing one.
The WordPress toolkit is dead weight for us
Bundled free, and we are a Contao shop. Worth naming so nobody counts it as value in the comparison.

Questions worth bringing to the review

Does anyone have hands-on time with Ploi, RunCloud or Enhance in production? Is there a panel that gives per-site isolation with a gentler operational learning curve? And is there a reason to keep cPanel that we have not accounted for — a client expectation, an integration, a workflow the team depends on that would cost more to rebuild than the licence saves?

Recommended sequence

Four moves, and the order matters

Ordered so that isolation is proven before we rely on it, and so that no step deepens our dependence on one person. The consolidation saving is tempting to take first, but it is the one move that depends on everything else working.

The billing calendar sets the window

Invoices go out between November and early January, so clients pay for the year up front. That means two things: the migration work should land between February and October, well clear of billing season, and any savings we capture mid-year drop straight to margin without touching a single invoice. It also means the November cycle is the natural moment to communicate anything client-visible.

  1. Now · targets $5,500/yr

    Template the Cloudflare rules

    Eighty-eight zones are currently tuned by hand. Build one standard rule set — rate limits on expensive paths, Contao-aware cache rules, AI crawler blocks — and push it to every zone through the Cloudflare API. Roughly 20 hours against the single largest labour line. It depends on nothing else and pays off whichever panel we end up on — and it converts John’s per-zone knowledge into a versioned file anyone can read, which is the cheapest key-person fix available to us. Write the SOP for pushing and rolling back a rule at the same time.

  2. February onward · proves the thesis

    Pilot Enhance on one new server

    Stand up a fresh instance and migrate 10–15 lower-stakes Contao sites. Then deliberately load-test one of them to confirm the containers hold and the neighbours stay up. That test is the whole decision — if per-site limits genuinely contain a storm, every other saving follows. Run this with two people, not one, and write the SOPs as you go. Enhance expects more sysadmin depth than cPanel, so budget $1,000–1,500 of ramp-up — spend it on two people learning together, with the second person drafting each procedure in Google Docs while Andy walks it through. Anything that cannot be written down clearly is a gap worth finding now rather than during an outage.

  3. Only after step 2 passes

    Move the heavy sites, then retire September

    Once limits are proven, September's resource-hungry sites can share a box safely and the instance comes out — $2,913 a year in compute, licence and Imunify seat. Doing this before the limits are proven would undo the exact protection September currently provides, so the order here is not negotiable. Note the two new sites landing on September before year end may make it simpler to place them on the pilot server from the start.

  4. By October · locks in $9,100/yr

    Migrate the rest and retire cPanel

    Move the remaining sites, drop the cPanel licences, and move the SOP set from Google Docs into Strattum as the finished reference. Wrap up before the November invoices go out so the new platform gets a quiet quarter ahead of billing season. The exit test has two parts: the second person provisions a server and onboards a client working only from the SOPs with Andy out of the room, and we restore one real site from a Backblaze backup end to end. If that works, the migration is done and the key-person problem is genuinely fixed. If it does not, we have found the gap cheaply.

Open questions

What we should check before committing