Digital sovereignty

A Dutch company. European infrastructure. European data.

For businesses that need to know exactly where their data lives and who can touch it — municipalities, healthcare, legal, manufacturing, logistics — veldhost is European end to end. No US hyperscaler in the serving path, nothing leaving the EU, and everything documented rather than promised.

European by design

Owned, operated and supported in Europe.

Your site, its database, its backups, its DNS and its email all run on infrastructure we operate ourselves in German datacenters (Falkenstein and Nuremberg). There is no US hyperscaler in the serving path, and site data does not leave the EU — we don’t even load fonts from a foreign CDN. We build to stay portable across European providers rather than tied to one, so your sovereignty never rests on a single vendor.

Dutch company

Registered in the Netherlands, invoicing with EU VAT, governed by Dutch and EU law. Your contract and your counterparty stay inside the Union.

EU data residency

Production compute, storage and backups all sit in Germany (Falkenstein, with nightly backup replication to Nuremberg); the processor agreement also permits Hetzner’s Finnish region. EU residency is a contractual commitment — not a setting you have to find.

No lock-in fences

Full exports of files, databases, DNS zones and mail. Leaving is a download, not a negotiation — sovereignty includes the freedom to walk.

Transparency

Who touches your data — published, not implied.

Sovereignty you can’t inspect is just a slogan. Our Data Processing Agreement carries a full sub-processor register: every party, what they process, where, and on what legal basis. The short version:

Hetzner (Germany)

Germany · Finland — within the EEA

Core hosting: compute, containers, storage, backups and our DNS nodes.

Stripe (Ireland)

EEA — EU SCCs + DPF

Payments and billing metadata. Card data is Stripe’s to control; only billing identifiers reach us.

Self-hosted mail

Germany · Finland — self-operated

Mailboxes when you enable email — run on our own EU infrastructure, not a third-party SaaS.

Openprovider (Netherlands)

Netherlands — within the EU

Our domain registrar. Receives the domain name and our own business contact — never your personal data.

This website and the Manage portal are served directly from our own infrastructure and our own authoritative nameservers (ns1/ns2.veldhost.eu) — no edge, CDN or third-party DNS provider sits in front of any veldhost property. New domains register through Openprovider in the Netherlands; a small number of older domains are still being migrated from our previous registrar. The authoritative, versioned register, transfer bases and details live in the DPA.

Read the full sub-processor register →
NIS2 alignment

Built the way the directive expects.

NIS2 raises the bar on how essential and important entities manage cyber risk across their supply chain — and your hosting is part of that chain. We can’t hand you a NIS2 certificate (no such certification exists for a provider of our size), but here is how our actual measures line up with what the directive asks for.

Risk management

Per-tenant container isolation, default-deny networking and hardware-key-only administration — each control is itemised on the security page.

Incident handling

Continuous monitoring with automatic alerting, a documented breach process, and controller notification within 48 hours.

Supply-chain transparency

A published sub-processor register — you can see and assess every party in the chain, which is exactly what NIS2 due diligence expects.

Encryption

TLS in transit on every site and admin surface; backups and secrets encrypted at rest. Details on the security page.

Patching & vulnerability management

Automated fleet-wide security updates and a daily CVE scan with alerting — the cadence is on the security page.

Business continuity

Encrypted backups replicated nightly to a second region, with one-click restore and a documented disaster-recovery runbook.

Whether NIS2 applies to your organisation depends on your sector and size — we’re happy to talk through where our platform fits your obligations, and to point you at the measures on our security page and in the DPA.

Compliance & certifications — the honest version

We won’t wear badges we haven’t earned. Here is exactly where we stand:

  • GDPR — today. A published Data Processing Agreement with a full sub-processor register and EU data residency.
  • NIS2 — aligned, not certified. Our measures map to the directive (above); we don’t claim a certificate that doesn’t exist for our size.
  • · ISO 27001 — planned. We do not hold ISO 27001 or SOC 2 today. Our information-security practices are already documented on the security page and in the DPA; formal certification is on the roadmap, not implied before the certificate exists.
  • · Sector standards — on request. Working in Dutch healthcare (NEN 7510), government (BIO) or a regulated vertical? Talk to us about your specific requirements before you commit.