We zitten in een publieke testfase — kijk gerust rond, maar bestellen kan nog niet. Bestellen kan vanaf 1 oktober 2026.
Digital sovereignty

A Dutch company.
European infrastructure. European data.

For businesses that need to know exactly where their data lives and who can touch it — municipalities, healthcare, legal, manufacturing, logistics — veldhost is European end to end. No US hyperscaler in the serving path, nothing leaving the EU, and everything documented rather than promised.

European by design

Owned, operated and supported in Europe.

Your site, its database, its backups, its DNS and its email all run on infrastructure we operate ourselves in German datacenters (Falkenstein and Nuremberg). There is no US hyperscaler in the serving path, and site data does not leave the EU — we don’t even load fonts from a foreign CDN. We build to stay portable across European providers rather than tied to one, so your sovereignty never rests on a single vendor.

Dutch company

Registered in the Netherlands, invoicing with EU VAT, governed by Dutch and EU law. Your contract and your counterparty stay inside the Union.

EU data residency

Production compute, storage and backups all sit in the EU (Germany and Finland). Our processor agreement commits to it — it isn’t a setting you have to find.

No lock-in fences

Full exports of files, databases, DNS zones and mail. Leaving is a download, not a negotiation — sovereignty includes the freedom to walk.

Transparency

Who touches your data — published, not implied.

Sovereignty you can’t inspect is just a slogan. Our Data Processing Agreement carries a full sub-processor register: every party, what they process, where, and on what legal basis. The short version:

Hetzner (Germany)

Germany · Finland — within the EEA

Core hosting: compute, containers, storage, backups and our DNS nodes.

Stripe (Ireland)

EEA — EU SCCs + DPF

Payments and billing metadata. Card data is Stripe’s to control; only billing identifiers reach us.

Self-hosted mail

Germany · Finland — self-operated

Mailboxes when you enable email — run on our own EU infrastructure, not a third-party SaaS.

Openprovider (Netherlands)

Netherlands — within the EU

Our domain registrar. Receives the domain name and our own business contact — never your personal data.

The portal and this marketing site use Cloudflare for edge and DNS; customer application traffic is not routed through it. New domains register through Openprovider in the Netherlands; a small number of older domains are still being migrated from our previous registrar. The authoritative register, transfer bases and details live in the DPA.

Read the full sub-processor register →

NIS2 alignment

Built the way the directive expects.

NIS2 raises the bar on how essential and important entities manage cyber risk across their supply chain — and your hosting is part of that chain. We can’t hand you a NIS2 certificate (no such certification exists for a provider of our size), but here is how our actual measures line up with what the directive asks for.

Risk management

Default-deny firewalls, per-tenant container isolation, and admin planes reachable only over mutual-TLS or hardware-key SSH.

Incident handling

Continuous monitoring with automatic alerting, a documented breach process, and controller notification within 48 hours.

Supply-chain transparency

A published sub-processor register — you can see and assess every party in the chain, which is exactly what NIS2 due diligence expects.

Encryption

TLS on every site and every admin surface; backups encrypted at rest before they leave the host.

Patching & vulnerability management

Fleet-wide automated security updates, extended-support maintenance, and daily vulnerability scanning with alerting.

Business continuity

Encrypted nightly backups replicated to a second region, with one-click restore and a documented disaster-recovery runbook.

Whether NIS2 applies to your organisation depends on your sector and size — we’re happy to talk through where our platform fits your obligations, and to point you at the measures on our security page and in the DPA.

Compliance & certifications — the honest version

We won’t wear badges we haven’t earned. Here is exactly where we stand:

  • GDPR — today. A published Data Processing Agreement with a full sub-processor register and EU data residency.
  • NIS2 — aligned, not certified. Our measures map to the directive (above); we don’t claim a certificate that doesn’t exist for our size.
  • · ISO 27001 — planned. We do not hold ISO 27001 or SOC 2 today. Our information-security practices are already documented on the security page and in the DPA; formal certification is on the roadmap, not implied before the certificate exists.
  • · Sector standards — on request. Working in Dutch healthcare (NEN 7510), government (BIO) or a regulated vertical? Talk to us about your specific requirements before you commit.

Sovereignty you can put in a tender.

Start a free trial, or reach out if you’re evaluating us for a regulated or procurement-driven project — we’ll answer your security questionnaire straight.