Your WordPress sites stay up.
Even when your server doesn't.
When your Primary server fails, Tergum automatically promotes your Standby to Primary — your site stays up and WooCommerce keeps taking orders. No manual intervention. No 3am phone calls.
Tergum is Latin for "back." We've got yours.
The problem
Downtime isn't a technical problem.
It's a business problem.
Every minute your WordPress site is down, you're losing sales, leads, and trust. Most hosting setups have a single point of failure. When it goes — and eventually it will — your site goes dark.
“Does thinking about this kind of scenario cause you to lose sleep?”
— Overheard on r/sysadmin
Your server fails at 2am
No one notices until a customer emails to say the site is down. By then you've lost hours of traffic.
Manual intervention takes too long
Even if you're watching, switching DNS manually takes 10–30 minutes and requires access you may not have.
You can't be everywhere
Agencies managing dozens of client sites can't monitor all of them simultaneously. One failure slips through.
Managed hosting HA requires you to move your sites. DNS-only failover is useless without live replication. DIY tools take days to set up and years to maintain. Until now, there was no off-the-shelf solution for people who own their own servers.
Read the full competitive analysis →How it works
Set up once. Protected forever.
No complicated networking. No firewall changes. Works on any servers you already have.
Install the agent (5 minutes)
Run our one-line installer on your Primary and Standby servers. Before setup proceeds, the dashboard shows you every change Tergum will make to your servers — MySQL replication user, SSH key exchange, inotify limits — and asks for your explicit acknowledgement. No surprises, no silent modifications. No inbound ports required — agents initiate outbound HTTPS connections.
We set up replication
Tergum automatically configures MySQL/MariaDB replication between your servers, syncs your WordPress files in real time, and verifies everything is working before marking setup complete.
We watch, you relax
Our independent monitoring node checks your site every 30 seconds from outside your network. If your Primary server stops responding — to us and to the internet — promotion begins automatically.
Your Standby becomes Primary
Within minutes, Tergum promotes your Standby to Primary, flips your Cloudflare DNS, and traffic flows seamlessly to the promoted Standby. WooCommerce orders keep processing. Your visitors notice nothing — and you get an immediate alert.
Original server rejoins as Standby
When your original server comes back online, Tergum alerts you. You re-establish it as a new Standby that replicates from the promoted server — picking up every order and post that came in during the outage. Once resynced, you choose whether to swap roles back or leave the promoted server as Primary permanently.
Features
Everything your WordPress sites need to stay online
Automatic Promotion
Detects failure within 30 seconds. Promotes your Standby to Primary and updates Cloudflare DNS automatically. Your site keeps running — no manual steps, no downtime window.
Real-Time Replication
MySQL/MariaDB binary log replication keeps your databases in lock-step. inotify + rsync keeps your WordPress files current.
Independent Monitoring
Health checks from an Oracle Cloud node — completely separate from your hosting. We see failures before your visitors do.
Instant Alerts
Email and push notifications (NTFY) on all plans. SMS escalation is a premium add-on (included on Sentinel). Be notified when anything goes wrong: server offline, replication stopped, disk space, promotion events.
Your Servers, Your Data
We never read your content or databases — only health metrics. Your data stays on your servers, under your control, always.
Flexible Promotion Policies
Conservative, Tolerant, Strict, or Manual — set per domain. Controls how aggressively each domain monitors for server failure and whether Tergum flips its DNS automatically. Set Manual and Tergum alerts you the moment failure conditions are detected — you approve from the dashboard before any DNS switch occurs.
Automated Setup
Our installer handles Tailscale networking, SSH keys, MySQL replication, Cloudflare Tunnel, and file sync. Most setups complete in under 30 minutes.
Multi-Site Support
One server pair protects multiple domains, each with its own health check URL and Cloudflare DNS zone. Works across any Cloudflare account — each domain can use a different CF token, so agencies managing clients who control their own DNS are fully supported. Tergum monitors every domain independently for site-specific alerts.
Works Behind NAT
Tergum agents initiate outbound HTTPS — no inbound firewall changes, no exposed ports. Your Standby can sit behind a residential NAT or corporate firewall. Just connect to the internet and you're protected.
🔐 No risk. No commitment.
- 30-day free trial — your card is on file but nothing is charged until day 31
- Month-to-month or yearly billing — no contract, no lock-in
- Cancel any time from your dashboard — service runs until the end of your paid period
- When you cancel, Tergum monitoring stops and the agent is removed from your servers — one command, clean exit
Add-ons
Go further when you need it
Shield gives you everything you need to stay protected. Add these when you want deeper visibility or faster escalation — or choose Sentinel and get both included.
Enhanced Monitoring & Alerts
A predictive layer that watches six signals across both servers — disk exhaustion forecast, memory pressure, CPU load trends, replication lag trajectory, response time drift, and web error rate spikes. When something is trending the wrong way, you hear about it before it becomes a problem.
Fully configurable thresholds per signal group. A weekly digest summarises the health of your servers so nothing slips through the cracks.
$5/mo add-on on Shield — included on Sentinel.
SMS Escalation
Critical alerts — server offline, promotion blocked, disk full, manual approval needed — go straight to your phone via SMS. Set up takes under a minute: enter your number, confirm with an OTP, and you're covered.
Only critical alerts reach you by SMS, so your phone only buzzes when it matters. Email and push (NTFY) are fully configurable — choose exactly which alert types you receive.
$5/mo add-on on Shield — included on Sentinel. Get both add-ons for $7.50/mo.
Pricing
Simple pricing. No surprises.
30-day free trial on all plans. Card required — nothing charged until day 31. Cancel any time.
For site owners and small agencies who need reliable protection without complexity.
- Up to 3 WordPress sites
- Automatic promotion with Cloudflare DNS
- MySQL/MariaDB replication setup
- Real-time file sync
- 30-second health checks
- Core alerts (disk, agent, promotion)
- Email support
Enhanced Monitoring & Alerts +$5/mo
SMS Escalation +$5/mo
Get Both for +$7.50/mo
Everything included. For agencies and professionals who want the full picture and nothing to think about.
- Up to 10 WordPress sites
- Everything in Shield
- Enhanced Monitoring & Alerts included
- SMS escalation included
- Installer + setup assist
- Priority support
Need coverage for more than 10 sites, a branded client portal, or a fully self-hosted deployment? We’ll scope it with you.
- Unlimited WordPress sites
- Your brand, your portal
- Dedicated onboarding
- Priority SLA
- Full setup assist
- Custom contract
All prices in USD. Canadian customers: GST/HST added at checkout based on province. Stripe handles all payment processing.
Requirements
Nuts & Bolts
Tergum has a few technical requirements. Check these before signing up — we'd rather you know upfront than discover a limitation at setup time.
Your Servers
- Two Linux servers — one running WordPress (Primary), one for Standby (failover target)
- Ubuntu 22.04 LTS or 24.04 LTS, or Debian 11+
- Both servers must run the same distro & major version
- Root or sudo access to run the Tergum installer (one-time — it handles all package installation and configuration automatically)
- Outbound HTTPS (port 443) — no inbound firewall changes required
Database
- MySQL 5.7+, MySQL 8.0+, or MariaDB 10.4+
- Same engine on both servers (MySQL or MariaDB)
- Within one major version of each other
- Binary logging enabled (Tergum checks this during setup)
- MySQL ↔ MariaDB cross-engine replication not supported
Web Server & PHP
- Nginx, Apache, LiteSpeed, or OpenLiteSpeed on the Primary server
- Nginx + Apache reverse-proxy stacks also supported (e.g. Nginx front-end with Apache backend on a non-standard port)
- PHP 7.4+ with standard WordPress extensions
- Both servers must use the same web server type and topology
- Standby can be a fresh OS install — Tergum auto-installs matching software versions during setup (Nginx and Apache only; LiteSpeed must be installed manually)
Cloudflare
- Free Cloudflare account
- Domain DNS managed through Cloudflare
- API token (DNS Edit + Tunnel Read) — setup wizard walks you through creation
- Cloudflare Tunnel is installed on your Standby server during setup and provides its public HTTPS endpoint
Tailscale
- Free Tailscale personal or team account
- Installed on both servers
- Key expiry disabled (prevents automation from breaking on token renewal)
- Tailscale creates a secure private network between your servers — no VPN configuration or open firewall ports needed
Current Limitations
- Shared hosting, cPanel, or Plesk environments
- Windows servers
- Mixed OS versions (e.g. Ubuntu 22.04 Primary + 24.04 Standby)
- Non-WordPress CMS (Joomla, Drupal, Ghost, etc.)
- Active-active (multi-primary) database replication
FAQ
Common questions
Do I need to change my hosting provider?
No — as long as both your servers meet the requirements listed on this page, your hosting stays exactly as-is. Your current server becomes the Primary; a second matching server becomes the Standby.
How long does promotion actually take?
Tergum checks health every 30 seconds. After 2 consecutive failed checks (~1 minute), promotion begins. DNS updates via Cloudflare propagate within seconds for most visitors. Total time from failure to traffic on Standby: typically under 2 minutes.
What if I want to approve promotions manually?
Set your policy to Manual. Tergum will alert you immediately when promotion conditions are detected — Primary down, Standby ready — and wait for you to approve from the dashboard. It won't act without you.
Do my servers need to be in the same location?
No. Tergum uses Tailscale for secure networking between your servers, so they can be in different data centres, different countries, or different providers entirely. The only requirement is that both connect to the internet.
Does each domain fail over independently?
No — the server pair is the unit of failover. When your Primary server goes down, every domain on that pair promotes to the Standby together. There’s no per-domain failover. This is worth considering when deciding which sites to host on the same server pair — sites that you’d always want to fail over in unison are natural candidates to share a pair.
Does it work with WooCommerce?
Yes — and this is where Tergum's promotion model really shines. When your Primary fails, the Standby is promoted to Primary: it keeps accepting orders, processing checkouts, and writing to the database. Your WooCommerce store never stops. When your original server comes back and resyncs, every order placed during the outage is already there on the promoted Standby server — nothing is lost.
The only caveat: any transaction that was literally in-flight at the exact moment of failure (mid-commit, before replication could stream it) may not appear. For most stores this is negligible — the replication lag is typically under a second.
What happens when my original server comes back online?
Tergum detects the heartbeat returning and immediately alerts you: "Your original server is back online — but your site is still running on the promoted Standby." The original is stale at this point; it missed every write that went to the promoted server during the outage.
From your Tergum dashboard you click Resync. Tergum then handles everything:
- clones the current database from the promoted Primary to the original server
- configures replication so the original starts following the promoted server, and waits for it to catch up
Once fully in sync, an Initiate Failback button appears if you want to swap roles back — or you can simply leave the promoted server as Primary permanently. Either way, not a byte of data is lost.
For content-only sites (blogs, brochures — nothing transactional), you can enable auto-revert: Tergum handles the entire recovery automatically. When the original server comes back online, Tergum immediately resyncs the database from the promoted server to the original, monitors replication lag, and only flips DNS back once the original is fully caught up. The result is a true return to the initial state — no human involvement, no divergence, no stale data. You'll get a notification when it's done.
Why do I need to click Resync manually? Can't Tergum just do it automatically?
For transactional sites (eCommerce, membership, contact forms) — three reasons, all in your interest:
Safety. Automatically starting a full database clone on a server the moment it comes back online — without a human confirming it's stable — is risky. A recovered server that crashes again mid-resync leaves replication in a broken state. A 30-second confirmation window costs you nothing and protects you from that scenario.
Technical necessity. The recovered server can't just "pick up where it left off." Its binary log position is out of date and its data is stale. A full clone from the promoted Primary is required to re-establish a clean replication baseline — that's not something that can happen silently in the background.
Your data, your call. For eCommerce sites especially, you may want to review what happened during the outage — orders taken, inventory changes — before committing to the resync. The promoted server is your live database. We'd rather you confirm you're ready than have us automatically overwrite the original without your say-so.
One thing worth keeping in mind: Resync operates at the server level. All domains on the pair are affected simultaneously — you can't selectively resync just one site.
In practice the manual step is a single button click. Tergum does all the heavy lifting from there.
What MySQL/MariaDB versions are supported?
Tergum supports MySQL 5.7+, MySQL 8.0+, and MariaDB 10.4+. Primary and Standby must run the same database type and be within one major version of each other. Tergum validates compatibility before completing setup.
What web servers are supported?
Tergum supports Nginx, Apache, LiteSpeed Enterprise, and OpenLiteSpeed on Ubuntu/Debian. Nginx + Apache reverse-proxy stacks (where Nginx handles incoming traffic and proxies to Apache on a non-standard port) are also supported — common in some panel-managed setups.
Primary and Standby must use the same web server. LiteSpeed and OpenLiteSpeed are cross-compatible with each other since both use .htaccess for routing. Tergum detects your stack automatically and validates compatibility before completing setup.
Two notes on auto-install limitations: if your Primary runs LiteSpeed, install it on the Standby first (LiteSpeed Enterprise requires a license key; OpenLiteSpeed is free and installs in minutes). If your Primary uses a Nginx + Apache reverse-proxy stack, install both Nginx and Apache on the Standby first. In both cases, as long as the software is already present when you run the Tergum installer, setup proceeds exactly as normal — Tergum detects what’s installed, validates compatibility, and handles all configuration and syncing from there.
What does Tergum actually change on my servers?
We think you should know exactly what runs on your servers before you sign up. Tergum makes three categories of changes:
Tergum infrastructure — files and services Tergum owns and removes when you cancel: the agent binary, file-sync watcher, and emergency recovery endpoint. These exist solely to support Tergum's operation and have zero impact on your WordPress site.
Required setup changes — changes to your server that are necessary for replication to work: a MySQL replication user (tergum_repl), binary logging configuration, an SSH key for file sync, an inotify kernel parameter, and MySQL read-only mode on the Standby. These are shown to you verbatim in the setup wizard and require your explicit acknowledgement before setup proceeds. They're also enumerated in our Terms of Service.
Optional site operation changes — enhancements like wp-cron management or per-domain web server logging that you opt into through the dashboard. These require your explicit consent, are reversible, and you'll receive an email when they're applied.
Every automated change is logged in your dashboard's Activity Log so you always know what Tergum has done on your servers.
What happens if I cancel?
Your subscription runs to the end of the billing period, then Tergum monitoring stops and the agent is cleanly removed from your servers.
What gets removed: the Tergum agent, the file-sync watcher, and the emergency recovery endpoint — everything that requires our backend to function.
What stays: MySQL replication (your Standby keeps syncing), Cloudflare Tunnel (your CF account, your tunnel), Tailscale (your network), and your SSH keys. Your servers keep running exactly as before — you just lose the automatic promotion, monitoring, and DNS-failover layer. If you re-subscribe, protection is restored immediately with no re-setup required.
If you want a completely clean slate, our documentation includes step-by-step instructions for removing MySQL replication and any other Tergum-configured infrastructure at your own pace.
Is my data safe?
Tergum agents send health metrics (disk usage, CPU, replication status, etc.) to our backend for monitoring. We never read or store your WordPress content, customer data, or database contents. Your data stays on your servers. See our Privacy Policy for full details.
Still have questions? Contact us →
We typically respond within a few hours.
Your sites deserve better than hoping nothing breaks.
Tergum runs quietly in the background, watching every heartbeat of your server, ready to act the moment something goes wrong. Most customers never need to think about it — which is exactly the point.
No commitment. Cancel before day 31 and pay nothing.