Who can reach your data
Every answer here is a term of the contract, not a description of good intentions. Each one names how you verify it at handover and how you check it afterwards.
What I can technically read
The honest starting point, because most providers avoid it. An administrator with full access to a server (root) can read what is on it. That is true of me, of Google, and of every managed provider that has ever told you your data is “encrypted”. The question is not whether it is possible — it is what stands between possible and happening, and whether you can tell.
Disks
The disks are encrypted while the machine is off (LUKS). That protects against a stolen or returned drive. It does not protect against me, and any provider implying otherwise is misleading you.
Password vault
Your password vault is encrypted before it reaches the server. It holds ciphertext it cannot decrypt. I cannot read a vault entry, and neither can anyone who walks off with the disks.
Mail and files
Mail and files can be read by an administrator (root). I commit not to, and to the controls below so that my word is not the only thing standing there.
The access journal
Every administrative action is logged to an append-only journal shipped off the machine, so an entry cannot be removed by whoever performed the action. You get read access to it. If I open your mailbox, it is in there.
Remote support
Remote support needs your consent per session. You see the screen being shared, and I cannot start a session you have not accepted.
If you cannot accept an administrator having that much access at all, the honest answer is that you want services where the provider holds no key. I will tell you which of these can be run that way, rather than sell you the ones that cannot.
Which keys are whose
- Disk encryption
Me. Required to boot the machine unattended.
- Password vault
You, and only you. Derived from your passphrase, not recoverable by me.
- Backup encryption
You hold the primary key. I hold an operational copy for restores.
- Domain registrar
You. The account is in your name and paid by you.
- Certificates that encrypt the connection (TLS)
Issued and renewed automatically. No long-lived secret to lose.
Check the registrar line first. It is the difference between a provider you can leave and a provider you have to negotiate with.
Where the hardware is
Your machine is a physical server on my own premises in Busto Arsizio — not a rack in a datacentre, and not a VPS reselling someone else’s cloud. This is the strongest argument against me and you should hear it from me rather than find it.
What is committed
A locked rack, with me as the only person holding routine physical access. Battery-backed power (UPS) that shuts the machines down cleanly if the cut lasts. A business internet line on a fixed address, with a documented second line to fall back to (failover). Temperature monitoring with alerting. No cleaners, landlords or third-party staff with unaccompanied access.
What it does not give you
No manned security, no mantrap, no biometric access log. No N+1 power or cooling. No third party guaranteeing that the building stays powered and online. A certified datacentre would offer all four, and I am telling you it does not.
If your risk assessment requires a certified datacentre, that is a reasonable requirement and I will colocate your machine in one at cost. Raise it before we sign rather than after.
Backups
Schedule and copies
Nightly, encrypted and incremental. Three copies on two kinds of media with one offsite: the live machine, a local backup target, and a copy in a separate building.
Retention
Retention of 30 daily and 12 monthly snapshots.
Restore tests
Restores are tested twice a year, and the result is written into the report you receive. An untested backup is a hope, not a backup — and you are welcome to witness a test.
The offsite key
The offsite copy is encrypted with a key you hold. If my premises burn down with me inside, your data is still recoverable by you, without me.
Access, and how the machines are locked down
Administrative access
Administrative access requires multi-factor authentication, mine included. No shared accounts — every action attributes to a person.
Security updates
Security updates within 14 days. Vulnerabilities being actively exploited within 72 hours, with an out-of-band maintenance window where needed.
Internet exposure
Services are not exposed to the internet unless they have to be; the rest are reachable only over your own private connection (VPN). My own devices reach them through the same authenticated path as anyone else, with no private back door.
If something goes wrong
Notification
You hear from me in writing within 24 hours of my becoming aware, whether or not the scope is clear yet. You will not learn about an incident from somebody else.
Personal data
Where personal data is involved, GDPR Article 33 gives you 72 hours to notify the Garante. As your processor I give you what you need to make that notification. I do not make the decision on your behalf.
Post-incident report
A written post-incident report within 15 working days: what happened, what was reachable, and what has changed so that it does not recur.
What this page is not
It is not a certification. I hold no ISO 27001 and no SOC 2, and I will not imply otherwise. Those audit a management system, they cost more than a one-person business can carry honestly, and buying one to decorate this page would be the wrong signal entirely.
What you get instead is specificity you can check: named controls, named retention periods, an access journal you can read, and a restore test you can ask to witness. If a letter from an auditor is a hard requirement for your risk committee, say so plainly — that is a legitimate requirement, and it means I am not yet the right supplier.
If signing this off is your job, the family-office page puts the same controls in the order a risk review asks for them.