View through a tall steel and glass entrance wall into a stone arcade covered by a vaulted glass roof
Hosting by industry

Web Hosting for Engineering Firms

An engineering firm's website is a document library with a homepage attached. Capability statements, project sheets, spec pages, sample drawings, registration details. Storing all that is the easy part, so web hosting for engineering firms is really about deciding what is genuinely public, because a server will publish whatever you put in the folder and will not ask you twice.

Get Your Web Hosting Plan Get help choosing

Web hosting for engineering firms means running a document library

Look at what an engineering firm actually publishes and it is mostly files. A capability statement. Project sheets with photographs and a short scope. A line card. Sometimes a standard detail, a specification page, a sample calculation, a copy of a certificate of insurance. Marketing pages sit around those files, but the files are what people come for.

That shapes every hosting decision you will make, and it does it in a way that is different from most trades. A landscaper's site is pages. Yours is pages plus a cabinet, and the cabinet needs somebody who decides what goes in it.

Public, gated, and never

Sort every document into one of three piles before it goes anywhere near a server. Not after.

  • Public. Capability statement, service descriptions, project sheets you have written permission to show, staff biographies, registration and certification claims you can stand behind.
  • Gated. Material you will send on request. A detailed reference list, a longer past-performance package, anything with a client contact's name and number in it. Gated in practice means email, not a form that instantly hands over a file.
  • Never. Client drawings, calculations you were paid to produce, anything under an NDA, anything a client marked confidential, anything with export or security markings on it.

The third pile is the one that matters. Everything else is a preference. That pile is a liability.

Sort the three piles before you upload

We will sit down with your firm's public, gated and never piles and set the site up so the third one has nowhere to land. Since 1999, for Western New York firms. Call 716-771-2536.

Get Your Web Hosting Plan Ask us first 716-771-2536

The failure: an upload folder that got indexed

Here is how it happens, and it is almost never dramatic. Somebody needs to send a large file to a client and email will not take it. So they upload it to the website, because that is a place they can put a file and get a link. The link works. The client is happy. Nobody deletes the file.

Months later the folder has thirty files in it. A search engine finds one of them through a link in an old email signature, or the folder simply lists its own contents in a browser because nothing was set to stop it. Now a set of drawings with a client's site address on it is indexed and downloadable by anyone who searches the right phrase.

Nobody attacked you. Nobody guessed a password. The file was public the moment it was uploaded, because that is what a web server is for. The only thing that changed later was that somebody found it.

How to find out what is already up there

  1. List every folder that receives uploads

    Look in the file manager in your control panel, not in the website's menu. Menus only show pages somebody linked to. The folders usually have names like files, uploads, docs, ftp or a person's initials.

  2. Search for your own domain and file types

    Search a search engine for your domain name restricted to PDF and drawing file extensions. You will find things nobody remembers uploading. Do this before a client does it.

  3. Turn off directory listing

    If someone can visit a folder address and see a list of its contents, that setting is on. It should be off on every site. It is one line in the server configuration and any competent host or web company can do it in minutes.

  4. Delete rather than unlink

    Removing the link to a file does not remove the file. It only removes the signpost. Delete the file itself, and remember that anything indexed will need a removal request as well.

  5. Give file transfer its own home

    Use business email with proper attachments, or a client file-sharing service, or a genuinely password-protected area. Do not use the public website as a drop box. That habit is the whole problem.

None of this requires a bigger hosting plan. It requires somebody to decide it is their job. If that person does not exist at your firm, that is the thing to fix first, and our website security page covers the ordinary hygiene that goes with it.

Controlled and client-confidential material

Some engineering work carries obligations that follow the document rather than the contract. Defence and aerospace work can be export controlled. A lot of civil and industrial work is covered by a confidentiality clause the client's lawyer wrote. Utility, transit and water projects often involve site information that nobody wants in public for reasons that have nothing to do with competition.

We are not going to tell you which rule applies to which drawing. That is a question for your own counsel and your compliance officer, and the answer changes by client and by contract. What we can tell you is the practical shape of the problem, because it is the same every time.

  • Publishing to a website is publication to the whole world, including anyone outside the country. That is exactly the distinction a lot of control regimes care about.
  • A password on a page is not a control regime. It is a speed bump, and it does not create a record of who accessed what.
  • Marketing does not always know what is restricted. The person who assembles the project sheets is rarely the person who read the contract.
  • A photograph can carry information the drawing did not. Location data in the file, a legible control panel label, a visible address plate.

The safe default for a public marketing site is that no client deliverable goes on it. Show the work in words and in photographs you have cleared. If a client wants to see technical depth, send it to them, and let sending it be a decision somebody makes each time rather than a folder that sits open.

Check with your own adviser before publishing anything you received from a client, and before publishing anything produced under a government contract. Treat that as the rule and treat exceptions as approvals you can point to in writing.

Capability statements and past performance

If you chase public work, your website has a second audience that behaves nothing like a normal visitor. Somebody at an agency, or at a prime looking for a subconsultant, is checking whether you are real and whether you have done this before. They spend about a minute.

They want a few specific things and they want them without a phone call. Your legal entity name as registered. Your business classifications, if you hold any. The disciplines you actually practise. A short list of projects with owner, scope, and roughly when. A named contact who answers.

Make the capability statement findable and current

Most firms have one, and most firms have it as a PDF from three years ago sitting on a page nobody links to. Two fixes, and neither is expensive. Put the same content on the page as ordinary web text so it can be found by search, and keep the PDF as the version somebody attaches to an email. Then put a revision date on it, visible, so a reader knows whether to trust it.

Past performance is the part that ages worst. A project sheet from a job that closed in 2019, with a reference contact who has since retired, is worse than no sheet. Set a calendar reminder to review the list once a year. That review is also the moment to check that every project on it is still one you have permission to name.

One more thing that costs nothing. Use email at your own domain on every one of those documents. A capability statement with a free webmail address on it reads as a firm that is between things. Our business email page explains what that involves if you are still on a free address.

An inventory of your upload folders

Give us the login and we will list what is in the upload folders, what a search engine has already indexed, and what should come down. If nothing is wrong, we will tell you that instead of selling you a bigger plan.

Check my folders Ask us first 716-771-2536

Registration by state and by discipline

Professional registration is a claim, and claims on a website need to be exact. Buyers check them, competitors check them, and boards do occasionally take an interest in how a firm describes itself.

The practical difficulty is that registration is per state, per discipline, and often per firm as well as per individual. A principal registered in New York and Pennsylvania does not make the firm licensed everywhere it has a project photograph. Some states also regulate what a firm may call itself and how it may advertise engineering services.

  • Say which states, plainly, and keep the list on one page you can edit rather than scattered through the site.
  • Distinguish individual registration from firm authorisation. They are different things and readers who matter know the difference.
  • Name the discipline. Civil, structural, mechanical, electrical, environmental. Do not let a nav label imply a discipline nobody at the firm holds.
  • Take a state off the list the month a registration lapses, not at the next website review.
  • If you are unsure what your board allows you to say, ask them or ask your counsel. Advertising rules for licensed professions vary and we are not the right source for that answer.

The hosting connection here is small but real. A registration list is content you will change several times a year, so it needs to live somewhere you can edit in five minutes without calling anyone. If updating one line on your site currently means emailing a web company and waiting, that is a maintenance problem worth solving, and taking over a website covers what to collect if you are moving that work in-house.

Who should not build a document library

A one-person consulting engineer, and this covers more firms than the industry likes to admit.

If you are a sole practitioner working on referral, your site's job is to prove you exist, say what you do and how you are registered, and give somebody a way to reach you. That is four or five pages. A document library on that site is an empty room you now have to keep clean, and every file in it is a file you have to remember you published.

  • You do not need a large plan. Text pages and a handful of photographs are among the lightest things you can put on a server, and an entry shared hosting tier covers it comfortably.
  • You do not need a client portal. You have a phone and an email address, and a portal nobody logs into is a login page waiting to be attacked.
  • You do not need a big storage allowance for files you should not be publishing anyway.
  • You do need email at your own domain, because that is the credential a client actually notices.

Where spending more is genuinely justified: you have staff who upload material without a review step, you run a real gated area with client accounts in it, you host an application rather than a set of pages, or your firm has a compliance obligation that requires access records. Those are reasons. Having fifteen employees is not one on its own.

And if you are already paying for a managed plan for a five-page site with no logins on it, you are buying maintenance for machinery you do not run. Say so to whoever sold it and ask what it is protecting.

How AldoMedia helps

AldoMedia has built and looked after websites for Western New York businesses since 1999. We are an independent authorised reseller rather than the operator of the underlying platform, which means we set the account up, we help you get the site onto it, and we tell you when the plan you are already paying for is the right one.

For an engineering firm the useful first job is usually an inventory. What is in the upload folders, what is indexed, what should never have gone up, and who at the firm owns the answer from now on. That is an afternoon of work, not a project.

Call 716-771-2536 or tell us what your site runs on. If your current arrangement is fine, that is a perfectly good outcome and we will say so.

Common questions

Engineering firm website questions

Can I put sample drawings on our website?

Only ones you produced and own outright, with nothing client-identifying on them, and preferably redrawn as an illustration rather than lifted from a deliverable. Anything a client paid for is theirs, and anything under a confidentiality clause stays off. If you want to show technical depth, describe the work in words and send the detail to people who ask.

We use the website to send large files to clients. Is that a problem?

Yes, and it is the most common one we see at engineering firms. A file in a web folder is public whether or not you linked to it, and those folders are never cleaned out. Use email attachments, a proper file-sharing service, or a genuinely access-controlled area instead, and go and look at what is sitting in those folders today.

How do we know if our project files are already indexed by Google?

Search your own domain restricted to document file types and see what comes back. Then open the folders in your hosting control panel's file manager, because that shows files nothing links to. Turning off directory listing stops a folder from displaying its own contents to anyone who visits the address.

Should our capability statement be a PDF or a web page?

Both, doing different jobs. The web page version can be found by search and read on a phone, which the PDF cannot. The PDF is what somebody attaches to an email or drops into a procurement portal. Keep the two saying the same thing and put a visible revision date on each.

Is it safe to list the states we are registered in?

Listing them is normally expected, and buyers check. The risk is not listing them, it is listing them loosely: mixing individual registration with firm authorisation, or leaving a lapsed state up. Keep the list on one page you can edit quickly, and check with your board or your counsel about what your profession allows you to claim in advertising.

Do we need a client portal on our site?

Most firms do not. A portal is a login page, a set of accounts and a support obligation, and firms that build one often find clients keep emailing anyway. Build one when clients are actively asking for it and somebody will own the accounts. Until then it is an attack surface you added on purpose.

Related

Website Security

The ordinary hygiene behind an accidental publication: folder listings, uploads, logins and who is watching.

Read about website security

Business Email

Email at your own domain, which is what belongs on a capability statement and on every proposal.

Read about business email

Shared Hosting

The plan type most engineering firm sites belong on, and what the higher tiers actually change.

Read about shared hosting

Every trade we cover is listed on hosting by industry.

Hero image: David Adam Kess, CC BY-SA 4.0, via Wikimedia Commons. Cropped.

Find out what your site is already publishing

Tell us what your firm's site runs on and we will look at what is sitting in the upload folders. If the answer is nothing worrying, that is the report you get.

Get Your Web Hosting Plan Get help choosing

Or call 716-771-2536 and tell us what the site has to do. If the plan you are already on is the right one, we will say so.