Security
How we protect the apps and data we host for clients.
Last updated:
This is a summary of the security measures in Annex II of our data processing agreement. Clients receive the full annex with their DPA.
Our measures
EU and UK hosting
Client apps and databases run on Hetzner servers in Germany or Finland, or on DigitalOcean in its EU or London regions.
A separate database for each app
Each client app has its own database with its own credentials. Apps do not share databases or database users.
Databases are not on the internet
Databases do not accept connections from the public internet. Only the apps that use them can connect.
Private networking
Apps and databases talk to each other over private networks managed by Coolify, our deployment platform.
TLS everywhere
Every site we host is served over HTTPS, with certificates from Let's Encrypt. Plain HTTP requests are redirected to HTTPS.
Off-site backups
Backups are stored off-site on DigitalOcean, away from the servers they protect, and expire after 90 days. We test restores regularly.
SSH keys and MFA
Servers accept SSH keys only; password login is disabled. Signing in to Coolify, which deploys and manages our servers, requires multi-factor authentication.
Regular patching
We apply operating system and software security updates every week.
A written breach procedure
We have a written procedure for handling personal data breaches, including telling affected clients within 48 hours.
Dedicated servers
Most client apps run on a dedicated server that no other client uses. Where a client agrees, their app shares a server with other clients' apps.
Reporting a security issue
If you think you have found a security problem in anything we run, email privacy@hexastudios.co. Please do not share details publicly until we have had a chance to fix it.