All systems operational Your IP: 216.73.216.38 info@cloudhosting.lv +371 66 66 29 69 Client area
Trust and security · CloudHosting

Trust and security: where your data lives and who can reach it

CloudHosting SIA, a Latvian IT infrastructure provider since 2016, keeps client data in the EU by default, in the Tier 3+ data centre in Riga that it runs itself on its own network AS58269, with daily backups kept for 7 days on VPS and 14 days on web hosting, and monitoring and incident response 24/7.

This page puts in one place what a buyer checks before signing: where the servers stand, who can reach them physically and remotely, how backups and incidents work, where we stand on GDPR, NIS2 and DORA, and what we do not have.

  • Data in the EU by default
  • A data centre in Riga we run ourselves
  • Facts you can check, no certificate claims
Data protection in the EU: a document and a shield with a lock

Where your data lives

By default, in Riga. Other locations are used only for the services listed here.

Riga, Latvia

Default for every service

Web hosting, server colocation, the company infrastructure we run, and VPS and dedicated servers ordered for Riga live in the Tier 3+ data centre in Riga that we run ourselves, not in racks rented from another operator. Everything this page says about physical access applies here.

Amsterdam

Second region, in the EU

VPS and dedicated servers ordered for the Netherlands, the ready 10 Gbps servers included, run in Amsterdam, on our own servers and IP addresses; the building belongs to a local data centre operator. You choose the region when you order.

S3 object storage

EU, several data centres

Object storage is a managed service replicated across several independent data centres inside the European Union, so losing one site does not take your data with it.

Outside the default

Only when a project asks for it

Capacity in Dubai (DXB1) is brought online on request, for projects that need a location outside the EU. Bare metal GPU clusters go into a data centre in Europe chosen for the project and named in the contract.

Physical security of the Riga data centre

We describe physical protection in outline only and do not publish the details. This is what it means for you.

Guarded

The data centre is guarded. How exactly is not something we publish.

No visitors inside

Visitors, clients included, are not admitted to the data centre. Nobody walks in to look around or to work on a server themselves.

Hand-over at our office

You bring your equipment to our office and hand it over there; our engineers install it in the rack and connect it.

A few specialists

Access to the data centre is limited to a small number of our own specialists.

Redundancy

Every critical system has at least one independent reserve, so a component can fail or be taken out for maintenance while the load carries on.

  • Power: N+1 with UPS and a diesel generator
  • Cooling: N+1
  • Network: two uplinks behind a BGP core

See the redundancy scheme →

Network and backups

Network

We announce our own IP address space over our own BGP network.

  • Own network AS58269 with redundant uplinks
  • The Riga data centre is carrier-neutral: carriers present at the site can be reached over a cross-connect
  • Check it yourself: the IP addresses of our Riga services are registered to us in the public RIPE database

Backups

  • VPS: daily backups kept for 7 days, stored separately from the server
  • Web hosting: daily backups kept for 14 days on separate storage; restore a file, a database or the whole account from cPanel yourself
  • Company infrastructure we run: the backup schedule, the retention and the recovery targets are written down for each project

For data you cannot afford to lose, keep one more copy outside any single provider, us included.

Access and incidents

Access to your systems

On systems we administer for you, each of our engineers works under a named personal account, not a shared login, and that access can be revoked.

On a service you run yourself, such as an unmanaged VPS or a dedicated server, you hold the administrator access and decide who else gets an account.

Support and incidents

  • Monitoring and incident response run 24/7
  • Engineers answer on working days 9:00-17:00 Riga time, in English, Latvian and Russian
  • An incident that stops your work is handled at once; other alerts outside working hours are picked up the next working morning
  • 99.9% availability is our target, not a guarantee written into the standard terms

Live service status →

GDPR, NIS2 and DORA: what we provide

These laws put the duty on your company, and no hosting provider can take it over for you. What a provider can do is make the technical measures real and give you the facts your records need. We do not certify compliance.

GDPR

Data in Riga stays in the EU and under EU law, and your contract is with an EU company, so the location and the supplier are easy to name in your records of processing. For your own GDPR duties, such as records, policies or an outsourced data protection officer, our data protection specialist can help.

Data protection services →

NIS2

If your company is a subject of the Latvian Cybersecurity Law, a supplier can provide the measures: servers in the EU, backups with written recovery targets, named access, firewalls and incident response 24/7. The duty to register, report and assess stays with you.

NIS2 in Latvia: thresholds and deadlines →

NIS2 checklist for Latvia: the 10 measures and the evidence →

DORA

DORA makes banks, insurers, investment firms and other financial entities manage the risk of their ICT suppliers. For that assessment you get the facts on this page, our standard terms and answers from an engineer. If your contract needs clauses beyond our standard terms, name them at the start and we will tell you honestly which ones we can accept.

Our terms of service →

Want an independent look at your own systems first? From 200 EUR for an IT audit of your network, servers, backups and access, a fixed fee agreed before we start, with a prioritized action plan. IT audit →

No ISO 27001 or SOC 2: what we show instead

CloudHosting does not hold ISO 27001 or SOC 2 certification, and Tier 3+ describes how the Riga data centre is built, not a certificate. Instead of a logo, we give you things you can check.

  • This page, with the date its facts were last checked
  • Our terms of service, public before you order: invoices in EUR, nothing charged automatically, data kept for at least 30 days after a service is blocked for non-payment. Terms of service
  • The company in the Latvian Register of Enterprises: CloudHosting SIA, registration number 40103966259
  • Our network AS58269 and the IP addresses of our Riga services in the public RIPE database
  • A free 30-minute call with an engineer who answers your security questions before you sign. Book a free 30-minute call

Partner statuses we hold: Fortinet authorised partner and Microsoft partner.

The company behind the contract

CloudHosting SIA is a Latvian company in the EU, operating since 2016, registration number 40103966259. Contracts are under Latvian law, invoices are in EUR and nothing is charged automatically: to stop a service, you simply do not pay the next invoice.

At a glance

Key facts about security at CloudHosting

Short answers to the questions a security or procurement review asks first.

CompanyCloudHosting SIA, registration number 40103966259, a Latvian IT infrastructure provider operating since 2016; an EU company
Where data is storedRiga, Latvia (EU) by default, in the data centre we run ourselves; Amsterdam for the VPS and dedicated servers you order there, the 10 Gbps catalogue included; S3 object storage replicated across several data centres in the EU; Dubai (DXB1) only on request
Physical accessThe data centre is guarded and visitors are not admitted; equipment is handed over at our office and installed by our engineers; access is limited to a small number of our specialists
RedundancyTier 3+ design: N+1 power with UPS and a diesel generator, N+1 cooling, two uplinks behind a BGP core
NetworkOwn network AS58269 with redundant uplinks; the Riga data centre is carrier-neutral
BackupsVPS: daily, kept for 7 days, stored separately from the server. Web hosting: daily, kept for 14 days, on separate storage
Access to your systemsOn systems we administer for you, each engineer works under a named personal account, and that access can be revoked
SupportMonitoring and incident response 24/7. Engineers answer on working days 9:00-17:00 Riga time, in English, Latvian and Russian.
IncidentsAn incident that stops your work is handled at once; other alerts outside working hours are picked up the next working morning
Availability99.9% is our availability target, not a guarantee written into the standard terms
CertificationNo ISO 27001 and no SOC 2 certification. Partner statuses: Fortinet authorised partner, Microsoft partner
ContractWith CloudHosting SIA under Latvian law; invoices in EUR, nothing is charged automatically; a data processing agreement (DPA) is signed on request

Checked:

Security questions buyers ask

Where does CloudHosting store my data?

CloudHosting stores client data in its own data centre in Riga, Latvia, inside the EU, unless you order a service in another location. VPS and dedicated servers ordered for the Netherlands, the ready 10 Gbps servers included, run in Amsterdam, S3 object storage is replicated across several data centres in the EU, and capacity in Dubai (DXB1) is brought online only on request, for projects that need a location outside the EU. You choose the location when you order, so it is known before the contract. Web hosting, server colocation, the company infrastructure we run, and VPS and dedicated servers ordered for Riga stay in Riga.

How is the Riga data centre protected physically?

The CloudHosting data centre in Riga is guarded, and visitors, clients included, are not admitted to it. Clients bring their equipment to our office and hand it over there, and our engineers install it in the rack; access to the data centre itself is limited to a small number of our own specialists. We keep the public description of physical security to this outline on purpose and do not publish the measures in detail. Power, cooling and network redundancy are described separately, above on this page and on the data centre page.

What redundancy does the data centre have?

The CloudHosting data centre in Riga follows a Tier 3+ design: N+1 power with UPS and a diesel generator, N+1 cooling and two uplinks behind a BGP core. N+1 means every critical component has at least one independent reserve, so a part can fail or be taken out for maintenance while the load carries on. Tier 3+ describes how the site is built; it is not a certificate issued by an outside body. The data centre page shows the redundancy scheme with the paths for power, cooling and network.

How long do you keep backups?

CloudHosting keeps daily VPS backups for 7 days and daily web hosting backups for 14 days, in both cases on storage separate from the server itself. On web hosting you can restore a single file, a database or the whole account from cPanel yourself. For company infrastructure we run, the backup schedule, the retention and the recovery targets are written down for each project. For data you cannot afford to lose, we still recommend one more copy outside any single provider, and we say that about ourselves too.

Who at CloudHosting can access our systems?

On systems CloudHosting administers for you, each engineer works under a named personal account rather than a shared login, and that access can be revoked. That covers the company infrastructure, remote offices and other services we run for you. On a service you run yourself, such as an unmanaged VPS or a dedicated server, you hold the administrator access and decide who else gets an account. In the data centre, physical access is limited to a small number of our own specialists, and visitors are not admitted.

What happens if something breaks at night or at the weekend?

CloudHosting runs monitoring and incident response 24/7, and an incident that stops your work is handled at once, whatever the hour. Other alerts that arrive outside working hours are picked up the next working morning. Engineers answer requests, tickets and calls on working days from 9:00 to 17:00 Riga time, in English, Latvian and Russian. The status page shows the state of the shared platform; a problem limited to one server may not appear there, so write to support when something is wrong on your side.

Is there an SLA?

CloudHosting's standard terms do not contain an SLA: 99.9% availability is our target, not a contractual guarantee. We say it plainly because a figure that is not in the contract should not look as if it were. If your project needs contractual service levels, raise it before the offer, and we will tell you what we can commit to for that setup. The redundancy, monitoring and incident handling described on this page apply either way.

Do you have ISO 27001 or SOC 2 certification?

CloudHosting does not hold ISO 27001 or SOC 2 certification, and the Tier 3+ of the Riga data centre describes its design, not a certificate. Instead we show things you can check: this page with the date its facts were last checked, our public terms of service, the company entry in the Latvian Register of Enterprises (registration number 40103966259), our network AS58269 in the RIPE database and a free 30-minute call with an engineer. A data processing agreement (DPA) under Article 28 of the GDPR is signed on request. The partner statuses we hold are Fortinet authorised partner and Microsoft partner.

What does CloudHosting provide for our NIS2 and GDPR duties?

CloudHosting provides the technical side that NIS2 and GDPR expect from a supplier: servers in the EU, backups with fixed retention and, for the infrastructure we run, written recovery targets, named access that can be revoked, and monitoring and incident response 24/7, all from a Latvian company. The duties themselves stay with your company: under the Latvian Cybersecurity Law a subject registers, reports incidents and assesses itself, and under GDPR the controller keeps its records and policies. We do not certify compliance. If you need help with those duties, our NIS2 service, our data protection specialist and an IT audit from 200 EUR cover them.

We are a financial company under DORA. Can we use CloudHosting?

CloudHosting can serve a financial entity as an ICT supplier, but DORA puts the assessment of every ICT supplier on the entity itself: you need to know where the data is, who can reach it and what the contract says. This page answers the first two questions, our standard terms of service are public, and an engineer can go through your questions on a call. If your DORA register or contract policy needs clauses beyond our standard terms, name them at the start, and we will tell you honestly which ones we can accept. The DORA duties stay with you; no supplier can take them over.

Let us look at your company's infrastructure

Tell us how many people work with the systems, what runs today and your timeline. Engineers answer on working days 9:00 to 17:00 Riga time, monitoring and incident response run 24/7.