Trusted across 27 EU member states Client Area
Trust & Compliance

Data Sovereignty Isn't a Feature. It's the Foundation.

Every layer of our platform — physical, network and organisational — is built around one commitment: your data stays inside the EU, protected, and entirely under your control.

ISO/IEC 27001Independently certified
GDPR CompliantBy design, not by patchwork
AES-256 EncryptionAt rest and in transit
EU Data ResidencyGuaranteed, not optional
Certifications

Verified by Independent Auditors, Not Just Self-Declared

Every claim on this page is backed by a certificate or audit report available on request.

ISO/IEC 27001

Our information security management system is certified and re-audited annually by an accredited body.

GDPR Compliance Program

A dedicated data protection function, a documented DPA, and a public sub-processor list kept up to date.

TLS 1.3 Everywhere

Every connection to our infrastructure, including internal traffic between data centers, is encrypted in transit.

Physical Security

Biometric access control, 24/7 CCTV and on-site security staff protect every facility we operate.

DDoS Protection

Network-layer filtering is active on every server by default, absorbing attacks before they cause impact.

Data Residency Guarantee

Contractually guaranteed: your data is processed and stored only within our EU facilities, never outside.

How We Protect Your Data

Security Practices, Not Just Security Promises

These are the specific mechanisms behind every claim we make about data protection.

  • Encryption at rest and in transitAES-256 at rest, TLS 1.3 in transit, on every server without exception.
  • Strict, logged access controlsStaff access to customer data is role-based, individually logged, and reviewed every quarter.
  • Data Processing Agreement includedEvery hosting contract includes a DPA at no extra cost, ready to download from your client area.
  • 72-hour breach notificationIf something ever goes wrong, affected customers hear from us within 72 hours, matching GDPR Article 33.
0Data Breaches Since 2014
0hBreach Notification SLA
0%EU-Based Sub-processors
0/yrThird-Party Security Audit
Common Questions

GDPR & Security, Explained

What our customers' legal and compliance teams usually ask first.

Every hosting contract includes a Data Processing Agreement, downloadable at any time from the Legal section of your client area, no request needed.

Only with sub-processors strictly necessary to deliver the service, such as payment processors, all of which are listed publicly and are themselves GDPR compliant.

Affected customers are notified within 72 hours of us becoming aware of a breach, in line with GDPR Article 33, along with a clear explanation of impact and remediation steps.

Submit a request through your client area or by emailing our data protection team, and we respond within 30 days as required under GDPR Article 15.

Yes. Every sub-processor we use is contractually bound to GDPR-equivalent standards and is based within the EU or an approved adequacy jurisdiction.

Need Our Compliance Documentation?

Request our DPA, ISO certificate or latest audit summary — we'll send it directly to your inbox.