Data residency

Data and infrastructure in the European Union

For B2B customers, data location, environment isolation, and access control are design requirements — not marketing decoration. BaseCloud designs managed private / hybrid cloud with processing in the EEA by default; the object and hardware layer is provided by infrastructure partners, and we are responsible for operations, security, and contractual SLA.

EU residency

Storage and processing in the European Economic Area

By default, production data, backups, and operational logs remain in the EEA. This simplifies mapping to GDPR (transfers, processing agreements, DPIA) and expectations of enterprise and regulated-sector customers in the EU. Specific locations (country / region / facility) are set in the project and contract — after assessing system criticality and industry requirements.

What we agree with the customer

  • where production data lives vs replicas / backup,
  • which logs may leave the region (for example tool telemetry),
  • how the infrastructure subcontractor chain appears in documentation.

GDPR — context

Tenant isolation

Customer environment separation as a design requirement

Shared hosting with "soft" isolation does not meet enterprise expectations. In the BaseCloud model, each customer gets clearly separated boundaries: network, identity, storage, and admin panels. Isolation is not a "premium" toggle — it is an architectural assumption of managed cloud, scaled from Business (dedicated server / scope) to Enterprise (private / hybrid, often separate clusters and policies).

Practical layers

  • L2/L3 segmentation and firewall rules between tenants,
  • separate IAM accounts / roles — no shared superusers "for everything",
  • per-customer control of images, secrets, and backup paths.

Backup and DR

Copies and recovery procedures matched to criticality

Backup without RPO/RTO and restore tests is disk cost, not continuity. We match schedules, retention, and copy location to the package and system weight: daily backup with retention in Business; restore tests and DR scenarios in Professional / Enterprise. Replication and warm/hot standby apply where audit justifies the cost of low RPO.

Design principles

  • copies off the production volume itself (resilience to array failure),
  • clear owner of restore decisions and communication channel,
  • tests on a contractual cycle — not "once at go-live".

More: backup, RPO/RTO, and testing

Network and access

VPN, segmentation, hardening — according to threat model

Infrastructure access should not rely on public RDP/SSH "for convenience". We design paths: VPN or private links, jump hosts, MFA on panels, DMZ / app / data segmentation, and system hardening for an agreed threat model (for example fintech, healthcare, multi-tenant SaaS). Rule scope comes from assessment — not one template for everyone.

The BaseCloud model is fully managed: operator accountability. Client applications and data are handled through agreed channels (e.g. deploy, application panels), while OS-level administrative privileges stay with the operator.

Typical scope

  • east-west traffic control inside the environment,
  • attack surface reduction (closed ports, patching, CIS-like baseline),
  • access anomaly escalation paths — aligned with SOC / Neural Security Shield in Enterprise.

SOC, SIEM, and EDR · Neural Security Shield

Need residency and isolation mapped to your systems? View packages or return to the Data residency section.