Data residency
Data and infrastructure in the European Union
For B2B customers, data location, environment isolation, and access control are design requirements — not marketing decoration. BaseCloud designs managed private / hybrid cloud with processing in the EEA by default; the object and hardware layer is provided by infrastructure partners, and we are responsible for operations, security, and contractual SLA.
EU residency
Storage and processing in the European Economic Area
By default, production data, backups, and operational logs remain in the EEA. This simplifies mapping to GDPR (transfers, processing agreements, DPIA) and expectations of enterprise and regulated-sector customers in the EU. Specific locations (country / region / facility) are set in the project and contract — after assessing system criticality and industry requirements.
What we agree with the customer
- where production data lives vs replicas / backup,
- which logs may leave the region (for example tool telemetry),
- how the infrastructure subcontractor chain appears in documentation.
Tenant isolation
Customer environment separation as a design requirement
Shared hosting with "soft" isolation does not meet enterprise expectations. In the BaseCloud model, each customer gets clearly separated boundaries: network, identity, storage, and admin panels. Isolation is not a "premium" toggle — it is an architectural assumption of managed cloud, scaled from Business (dedicated server / scope) to Enterprise (private / hybrid, often separate clusters and policies).
Practical layers
- L2/L3 segmentation and firewall rules between tenants,
- separate IAM accounts / roles — no shared superusers "for everything",
- per-customer control of images, secrets, and backup paths.
Backup and DR
Copies and recovery procedures matched to criticality
Backup without RPO/RTO and restore tests is disk cost, not continuity. We match schedules, retention, and copy location to the package and system weight: daily backup with retention in Business; restore tests and DR scenarios in Professional / Enterprise. Replication and warm/hot standby apply where audit justifies the cost of low RPO.
Design principles
- copies off the production volume itself (resilience to array failure),
- clear owner of restore decisions and communication channel,
- tests on a contractual cycle — not "once at go-live".
Network and access
VPN, segmentation, hardening — according to threat model
Infrastructure access should not rely on public RDP/SSH "for convenience". We design paths: VPN or private links, jump hosts, MFA on panels, DMZ / app / data segmentation, and system hardening for an agreed threat model (for example fintech, healthcare, multi-tenant SaaS). Rule scope comes from assessment — not one template for everyone.
The BaseCloud model is fully managed: operator accountability. Client applications and data are handled through agreed channels (e.g. deploy, application panels), while OS-level administrative privileges stay with the operator.
Typical scope
- east-west traffic control inside the environment,
- attack surface reduction (closed ports, patching, CIS-like baseline),
- access anomaly escalation paths — aligned with SOC / Neural Security Shield in Enterprise.
Need residency and isolation mapped to your systems? View packages or return to the Data residency section.