Who can reach your data
Every answer here is a term of the contract, not a description of good intentions. Each one names how you verify it at handover and how you check it afterwards.
What I can technically read
The honest starting point, because most providers avoid it. An administrator with root on a server can read what is on it. That is true of me, of Google, and of every managed provider that has ever told you your data is “encrypted”. The question is not whether it is possible — it is what stands between possible and happening, and whether you can tell.
Disks are encrypted at rest (LUKS). That protects against a stolen or returned drive. It does not protect against me, and any provider implying otherwise is misleading you.
Your password vault is encrypted before it reaches the server. It holds ciphertext it cannot decrypt. I cannot read a vault entry, and neither can anyone who walks off with the disks.
Mail and files are readable by root. I commit not to, and to the controls below so that my word is not the only thing standing there.
Every administrative action is logged to an append-only journal shipped off the machine, so an entry cannot be removed by whoever performed the action. You get read access to it. If I open your mailbox, it is in there.
Remote support needs your consent per session. You see the screen being shared, and I cannot start a session you have not accepted.
If your threat model does not tolerate an administrator with root at all, the honest answer is that you want services where the provider holds no key. I will tell you which of these can be run that way, rather than sell you the ones that cannot.
Which keys are whose
- Disk encryption
- Me. Required to boot the machine unattended.
- Password vault
- You, and only you. Derived from your passphrase, not recoverable by me.
- Backup encryption
- You hold the primary key. I hold an operational copy for restores.
- Domain registrar
- You. The account is in your name and paid by you.
- TLS certificates
- Issued and renewed automatically. No long-lived secret to lose.
Check the registrar line first. It is the difference between a provider you can leave and a provider you have to negotiate with.
Where the hardware is
Your machine is a physical server on my own premises in Busto Arsizio — not a rack in a datacentre, and not a VPS reselling someone else’s cloud. This is the strongest argument against me and you should hear it from me rather than find it.
What is committed
A locked rack, with me as the only person holding routine physical access. UPS-backed power with clean shutdown on a sustained outage. Business connectivity on a static address with a documented failover. Temperature monitoring with alerting. No cleaners, landlords or third-party staff with unaccompanied access.
What it does not give you
No manned security, no mantrap, no biometric access log. No N+1 power or cooling. No facility uptime guaranteed by a third party. A certified datacentre would offer all four, and I am telling you it does not.
If your risk assessment requires a certified datacentre, that is a reasonable requirement and I will colocate your machine in one at cost. Raise it before we sign rather than after.
Backups
Nightly, encrypted and incremental. Three copies on two kinds of media with one offsite: the live machine, a local backup target, and a copy in a separate building.
Retention of 30 daily and 12 monthly snapshots.
Restores are tested twice a year, and the result is written into the report you receive. An untested backup is a hope, not a backup — and you are welcome to witness a test.
The offsite copy is encrypted with a key you hold. If my premises burn down with me inside, your data is still recoverable by you, without me.
Access and hardening
Administrative access requires multi-factor authentication, mine included. No shared accounts — every action attributes to a person.
Security updates within 14 days. Vulnerabilities being actively exploited within 72 hours, with an out-of-band maintenance window where needed.
Services are not exposed to the internet unless they have to be; the rest sit behind your VPN. My own devices reach them through the same authenticated path as anyone else, with no private back door.
If something goes wrong
You hear from me in writing within 24 hours of my becoming aware, whether or not the scope is clear yet. You will not learn about an incident from somebody else.
Where personal data is involved, GDPR Article 33 gives you 72 hours to notify the Garante. As your processor I give you what you need to make that notification. I do not make the decision on your behalf.
A written post-incident report within 15 working days: what happened, what was reachable, and what has changed so that it does not recur.
What this page is not
It is not a certification. I hold no ISO 27001 and no SOC 2, and I will not imply otherwise. Those audit a management system, they cost more than a one-person business can carry honestly, and buying one to decorate this page would be the wrong signal entirely.
What you get instead is specificity you can check: named controls, named retention periods, an access journal you can read, and a restore test you can ask to witness. If a letter from an auditor is a hard requirement for your risk committee, say so plainly — that is a legitimate requirement, and it means I am not yet the right supplier.