Built on trust, secured at every layer.
EasyCloudify™ is a managed platform that runs on certified public cloud infrastructure. Here's exactly how we protect your data, who can access it, and how responsibility is shared.
Three layers, clearly divided
Security is a partnership. Knowing who owns what keeps your data protected end to end.
You control
Your application code, configurations, credentials, users, and the content you store. You decide what data lives on the platform and who can access your accounts.
EasyCloudify™ secures the platform
The managed PaaS layer we own and operate — orchestration, patching, encryption, access controls, backups, monitoring, and incident response across your Services.
Certified providers secure the data centers
Physical and environmental security sits with the certified public cloud providers our platform runs on — audited under frameworks such as SOC 2, ISO 27001, and PCI DSS.
Real people, real accountability
Security run by engineers, not tickets.
Behind the platform is a team that owns day-2 operations — patching, monitoring, and incident response. When something needs attention, a senior engineer is on it, around the clock.
Your data stays yours
Encrypted end to end, controlled by you.
Content is encrypted with AES-256 at rest and TLS 1.2+ in transit. You decide what lives on the platform, where it resides (EU data residency available), and who can access it.
Built for scrutiny
Answers your auditors will accept.
From the DPA to inherited SOC 2, ISO 27001, and PCI DSS evidence, we give you the documentation to satisfy security reviews — without the runaround.
Certifications & compliance
EasyCloudify™ is a managed platform (PaaS) that runs on independent, certified public cloud infrastructure. We do not own data centers — we inherit their audited controls and add our own.
What certifications does EasyCloudify™ rely on?
EasyCloudify™ operates a shared-responsibility model. The public cloud infrastructure our platform runs on is maintained by providers who hold data-center certifications such as SOC 2, ISO 27001, and PCI DSS. On top of that infrastructure, EasyCloudify™ applies its own platform-layer controls — encryption, role-based access, patching, backups, monitoring, and incident response. Because we are a platform provider rather than a data-center operator, we do not claim data-center certifications in our own name; we rely on and inherit those maintained by our certified infrastructure providers.
Which compliance frameworks can EasyCloudify™ support?
Our platform controls and data-handling practices are designed to support customers with obligations under GDPR (including Article 32 security requirements), UK GDPR, the CCPA/CPRA, PCI DSS v4.0.1 (via our payment processor), SOC 2 Security criteria, HIPAA safeguards, and ISO 27001:2022. The specific framework that applies to your workload depends on your data and configuration — contact us to discuss your requirements.
Do you offer a Data Processing Agreement (DPA)?
Yes. EasyCloudify™ offers a Data Processing Agreement built for GDPR and CCPA/CPRA, with EU Standard Contractual Clauses and the UK Addendum included as annexes for international transfers. The DPA is executed privately with each customer alongside their order. Contact [email protected] to request it.
Can I keep my data in the EU?
Yes. For customers who require EU data residency, eligible Services can be provisioned in our EU regions (Amsterdam, Frankfurt, and London) so that your content is stored at rest within those regions. You select data residency when you provision your Service.
Data handling & access
Your data is yours. This section covers what we collect, how we use it, and who can access it.
What access does EasyCloudify™ have to the data I store?
EasyCloudify™ does not access the content you store on the platform except as needed to provide the Services, to respond to a support request you initiate, to maintain security and integrity, or where required by law. Administrative access is granted on a least-privilege, need-to-know basis, requires multi-factor authentication, and is logged and periodically reviewed.
How is my data encrypted?
Content at rest in platform-managed databases and object storage is encrypted with AES-256. Data in transit between you, the platform, and your end users is encrypted with TLS 1.2 or higher.
Which subprocessors process my data?
Personal data may be processed by infrastructure subprocessors including cloud hosting and storage providers, a CDN/security layer, a managed database provider, payment processing, and transactional email delivery. A complete, current subprocessor list is available under NDA or as part of our standard Data Processing Agreement. We provide at least 30 days' notice of any change to our subprocessors, with a right to object on reasonable data-protection grounds.
What data do you collect about me, and how do you use it?
As a controller for our own account relationship, we collect the account, billing, and usage data needed to provide and administer the Services, secure the platform, process payments, and provide support. We do not sell or share your personal data, and we do not use the content you host to train models or for advertising. See our Privacy Policy for details.
Infrastructure & network security
How the platform protects your workloads at the network and infrastructure layer.
How does EasyCloudify™ help me secure my network?
Every Cloud VPS includes a stateful Cloud Firewall you can manage from the control panel, with tag-based targeting so rules apply automatically across groups of servers. An optional Web Application Firewall (WAF) adds Layer 7 protection including OWASP Top 10 rulesets and bot filtering. Free SSL and DDoS mitigation are included.
How is the management and control plane secured?
Access to EasyCloudify™'s management systems is restricted to authorized personnel on a least-privilege basis, protected by multi-factor authentication, and monitored with centralized logging. Customer environments are segregated from one another on the platform.
Is my environment isolated from other customers?
Yes. Customer workloads run in isolated environments, and access controls prevent one customer from reaching another's resources. Managed databases are protected by a trusted-source firewall and TLS.
Payments & card data
How is my payment card information protected?
Payment card data is handled by a PCI DSS-compliant payment processor. EasyCloudify™ does not store full card numbers on its own systems — card details are tokenized and processed directly by the payment provider under its PCI DSS certification.
Vulnerability disclosure & abuse
How do I responsibly report a security vulnerability?
We welcome responsible disclosure. Email the details to [email protected]. Please give us a reasonable opportunity to investigate and remediate before any public disclosure, and do not access or modify data that is not yours while testing.
How do I report abuse on the platform?
Report suspected abuse, phishing, spam, or malicious content to [email protected] with as much detail as possible (URLs, IP addresses, timestamps). Our team investigates all reports and takes action under our Acceptable Use Policy.
Penetration testing
Can I run a penetration test against my own resources?
Yes, you may test resources you own on the platform, provided the testing is limited to your own Services and does not impact other customers or the shared infrastructure. Please notify us in advance at [email protected] so we can distinguish authorized testing from a real attack and avoid automated defenses interrupting your assessment.
Talk to our team about your compliance needs.
Request our Data Processing Agreement, a subprocessor list under NDA, or a security review for your workload.