Public testing phase We’re in a public testing phase — feel free to look around, but we’re not taking orders yet. Ordering opens 1 October 2026. See plans →

Security & vendor questionnaire

The questions you were going to ask, answered in writing.

Grouped the way SIG-Lite and CAIQ-style questionnaires are, so you can map answers across. Each answer links to the page or contract clause it is quoted from. Where a control or certificate does not exist, the answer says so.

Version 1.0 · reviewed 2026-09-09 · unanswered questions get a first response within two business days

Organisation & legal

What is the legal entity we would contract with?
Veldhost is the KvK-registered trade name of a Dutch sole proprietorship (eenmanszaak) established in Enschede, the Netherlands. The registered name, legal form, Chamber of Commerce (KvK) number, VAT number and registered office are printed on every legal page and in the vendor profile. Source →
Is the company a limited-liability company?
No. A sole proprietorship has no separate legal personality; the owner is personally liable to the extent the law provides. Our Terms therefore cap contractual liability rather than claim B.V.-style limited liability. Please assess this honestly stated fact alongside the mitigations: EU-only infrastructure, full data portability, no lock-in and a published exit path. Source →
How long has the company been operating?
The Veldhost trade name was registered with the Dutch Chamber of Commerce in August 2026. The platform is in a public testing phase; ordering opens on 1 October 2026. We state this plainly — it belongs in your risk assessment. Source →
Where is the company headquartered and where is the service operated from?
The Netherlands (Enschede). Operations, support and engineering are carried out from the Netherlands; infrastructure runs in Hetzner datacenters in Germany (see “Infrastructure & data residency”). Source →
What law governs the contract?
Dutch law, with jurisdiction of the Dutch courts, without prejudice to mandatory consumer rights. The Data Processing Agreement is likewise governed by Dutch law. Source →
In which languages do you provide contracts and support?
English, Dutch and Latvian for support. The Terms, SLA and AUP are published in English and Dutch; the English text is the contractual one. Source →
Do you have a named security and privacy contact?
Yes: security@veldhost.eu for vulnerabilities, questionnaires and incident matters; legal@veldhost.eu for contracts, the DPA and privacy requests. We have not appointed a statutory Data Protection Officer — GDPR Art. 37 does not require one for our processing — but the legal contact fulfils that role for enquiries. Source →

Infrastructure & data residency

Where is customer data hosted?
On infrastructure we operate ourselves in Hetzner Online GmbH datacenters in Germany (Falkenstein, with nightly backup replication to Nuremberg). The DPA also permits Hetzner’s Finnish region. All processing locations are inside the EU/EEA. Source →
Does any customer data leave the EU/EEA?
No. Customer Content, production compute, storage and backups all stay in the EU. The only non-EU party in the register is a legacy domain registrar (Canada, EU adequacy decision) that receives a domain-name string and our own business contact — never customer personal data. Source →
Is a US hyperscaler or US CDN in the serving path?
No. veldhost.eu, the Manage portal and customer sites are served directly from our own EU infrastructure and our own authoritative nameservers (ns1/ns2.veldhost.eu). No US cloud provider, CDN or DNS service is in the path, and fonts and assets are self-hosted. Source →
Is the infrastructure owned or resold?
Servers are rented from Hetzner (a German provider) and operated entirely by us: operating system, container platform, network policy, monitoring, backups and DNS. There is no intermediate managed-hosting reseller. Source →
How are tenants isolated from each other?
Every customer site runs in its own LXD system container with its own runtime, users and resource limits; customer databases listen on localhost only; container-to-container traffic is denied by default. Source →
Do you offer dedicated (single-tenant) infrastructure?
Yes. The Business plan is a dedicated EU server sized to the customer’s workload, ordered through a written quote, and it is the plan under which the 99.9% availability commitment with service credits applies. Source →
Do you offer multi-region failover?
Not today. Backups are replicated nightly to a second region for recoverability, but there is no automatic traffic failover. Multi-region failover options for Business plans are on the public roadmap. Source →

Access control & authentication

What authentication do customer accounts support?
Password plus a second factor: passkeys and hardware security keys (FIDO2/WebAuthn) are first-class, with an email one-time-code step-up as the fallback. The second factor is enforced for platform operators; customers enable it per account today, and account-wide enforcement for every team member is on the public roadmap. Sessions are bound to the browser and client address, so a stolen session cookie alone is not usable. Source →
Do you support SSO (SAML/OIDC) for customer accounts?
No, not currently. Team members get their own individual logins with per-site roles; account-level roles are on the roadmap. Source →
How is administrative access to the platform protected?
Operator access is hardware-key only (no password-only path), via a separate bastion with mutual TLS; root SSH is disabled; privileged actions are audit-logged. The customer portal has no administrative plane — platform administration is a separate SSH-only surface. Source →
Can customers delegate access to third parties (agencies, developers)?
Yes. A customer invites team members to specific sites with their own credentials, and can grant time-boxed SSH/SFTP access. Sharing the owner password is never required. Source →
How is API access controlled?
Personal API tokens with explicit scopes (read, deploy, manage, DNS), revocable at any time. The MCP server for AI assistants uses OAuth 2.1 or the same tokens. Anything that spends money or deletes data always hands off to an interactive confirmation by a human. Source →

Data protection & encryption

Is data encrypted in transit?
Yes. TLS on every customer site (certificates issued and renewed automatically, custom domains included) and on every management and internal admin surface. Source →
Is data encrypted at rest?
Backups are encrypted before they leave the host and stay encrypted in off-site storage. Environment secrets and stored credentials are encrypted at rest. Live container filesystems rely on physical datacenter security and tenant isolation rather than per-tenant disk encryption; tell us if your risk assessment requires the latter. Source →
What are the GDPR roles?
For Customer Content (your sites, databases, mailboxes, DNS) you are the controller and veldhost is the processor under a published Article 28 DPA. For account, billing, support and abuse data veldhost is an independent controller under the Privacy Policy. Source →
Do you sign a Data Processing Agreement?
The DPA is published and incorporated into every contract by reference. A countersigned copy on our letterhead is available on request to legal@veldhost.eu. Source →
Within what time do you notify a personal-data breach?
Without undue delay and in any event within 48 hours of becoming aware of a breach affecting Customer Content, with the information the controller needs for its own Art. 33/34 obligations. Source →
How do you handle sub-processor changes?
A versioned sub-processor register is part of the DPA. We notify customers at least 14 days before adding or replacing a sub-processor; customers may object on data-protection grounds and terminate the affected service if the objection cannot be resolved. Source →
What happens to data on termination?
At the customer’s choice we return Customer Content (file, database, DNS and mail exports; domain transfer codes) and/or delete it, including existing copies, within the export window in the Terms. Account deletion triggers automated teardown of the container. Only legally required records (e.g. invoices, 7-year Dutch fiscal retention) are kept. Source →
Can we audit you?
Yes. On reasonable written notice, no more than once per 12 months (or after a breach affecting you), satisfied first through documentation and, where genuinely insufficient, a proportionate remote or on-site audit under confidentiality and cost-allocation terms. Source →

Vulnerability, patch & change management

How are systems patched?
Operating-system and runtime security updates roll out fleet-wide automatically (daily sweep with automatic restart of affected services), backed by Ubuntu Pro extended security maintenance on the hosts. Source →
Do you scan for vulnerabilities?
Yes. A daily CVE scan (Trivy) runs across the fleet with alerting to the operations team. Source →
Do you commission independent penetration tests?
No independent penetration-test report is published today. Vulnerability reports from researchers are accepted under our responsible-disclosure policy and acknowledged within one business day. If your procurement process requires a third-party test, tell us — we will discuss scope and timing. Source →
How do you manage changes to the platform?
Every change ships through a reviewed pull request, an automated test suite that gates each deploy, atomic releases with instant rollback, and a public changelog entry for every production deploy. Source →
When is planned maintenance carried out?
Sunday 22:00–02:00 CET/CEST, at most two hours per month, with 3 / 5 / 7 business days’ notice for Starter / Pro / Business. Emergency security maintenance may happen at shorter notice. Source →

Backup, recovery & business continuity

How often are backups taken and how long are they kept?
Weekly backups are included on every plan. Daily backups with 30-day retention are the Business baseline and an add-on on Starter and Pro. Every backup, plus the platform databases, is replicated nightly to encrypted storage in a second region (Nuremberg), physically separate from the Falkenstein infrastructure serving the site. Source →
What are the RPO and RTO targets?
RPO: 7 days with weekly backups, 24 hours with daily backups. RTO for a standard restore: 2 business days (weekly), 1 business day (daily), 8 business hours on Business. These are objectives we work toward, not guarantees, and no backup credit applies. Source →
Can customers restore data themselves?
Yes. One-click restore of any restore point and backup download from the dashboard; a full production-site restore was live-validated in under one minute. Disaster-scale restores are runbook-driven; routine monthly restore drills are still being brought to a fixed cadence. Source →
What is the availability commitment?
Starter: best effort. Pro: 99.5% monthly target, no credits. Business: 99.9% monthly commitment with service credits (10% / 25% / 50% of the monthly hosting fee, capped at one month) once the dedicated setup is confirmed in the order. Source →
Is there a public status page and uptime history?
Yes. Live component health, 90 days of measured uptime, and a JSON feed. Uptime percentages cover only periods we actually measured; gaps render as gaps. Source →
How do you communicate incidents?
Through the status page, the dashboard incident view and email. Business customers get post-incident follow-up through priority support. Personal-data breaches follow the DPA process. Source →
What is your own business-continuity posture as a small vendor?
Stated plainly: veldhost is a small company. The mitigations are structural — standard open stacks (WordPress, PHP, Laravel, MariaDB, IMAP), full exports at any time, an unconditional contractual right to transfer any managed domain away (EPP code and lock removal within five business days, no fee), and backups in two regions. A customer can leave with everything in an afternoon. Source →

Incident response & monitoring

Do you have a documented incident-response process?
Yes: continuous monitoring with automatic alerting to the operations team, a documented breach process with the 48-hour controller notification in the DPA, and a customer-visible incidents manager with active/resolved history. Source →
What do you log and how long do you keep it?
Security and audit logs for privileged actions, web-server access logs per site (visible to the customer in the dashboard), and platform health samples. Retention follows the Privacy Policy. Customers can read their own site logs at any time. Source →
How do you handle abuse and takedown requests?
Under the published Acceptable Use Policy and abuse@veldhost.eu, with DSA-style notice handling. We do not suspend a paying customer for non-payment without at least one reminder and a reasonable time to pay. Source →
Is there a responsible-disclosure policy?
Yes. security@veldhost.eu; acknowledgement within one business day; reasonable time to fix before publication; no access to data that is not yours while testing. Source →

Sub-processors & supply chain

Who are your sub-processors?
Hetzner Online GmbH (Germany — compute, storage, backups, DNS nodes); Stripe Payments Europe Ltd (Ireland — payments, billing identifiers only); Openprovider / Hosting Concepts B.V. (Netherlands — domain registrar); OpenSRS / Tucows Inc. (Canada, legacy registrar being migrated, domain string only); and our own self-hosted mail service. The DPA register is the authoritative, versioned list. Source →
Does card data touch your systems?
No. Card data is entered into and stored by Stripe (PCI DSS Level 1 service provider). We receive payment references and statuses only. Source →
Do you use third-party analytics, tag managers or tracking on the service?
No third-party analytics or advertising trackers. Site analytics shown to customers are computed by us from our own web-server logs, with crawler and probe traffic excluded. Source →
How do you vet sub-processors?
Any provider that will carry customer data must be pinned to an EU location and added to the DPA register before use, with contractual data-protection obligations no less protective than the DPA. Mail is self-hosted precisely to avoid a third-party SaaS in the customer-data path. Source →

Application & platform security

Which stacks and versions do you run?
WordPress, PHP (multiple supported versions, switchable per site from the dashboard), Laravel and static sites, on nginx and MariaDB. Runtimes receive security updates automatically. Source →
Do you provide staging environments?
Yes. An exact staging copy of a site, password-gated, included with Pro and Business and available as an add-on on Starter. Source →
How are deployments done and can they be rolled back?
From the browser, SFTP, or git (veldhost Git, GitHub or GitLab) with deploy-on-push. Every deploy is tracked; rollback to any of the last ten releases is one click. Source →
Is there a machine-readable API?
Yes. A REST API documented as an OpenAPI 3.1 specification, a CLI, and a remote MCP server so AI assistants can operate the account under the same scoped tokens. Source →
Do you support DNSSEC and email authentication?
DNSSEC is available on our authoritative nameservers and can be enabled per domain from the dashboard. Mailboxes on your domain are provisioned with SPF, DKIM and DMARC records. Source →
What network protections are in place?
Default-deny host firewalls, rate limiting, per-tenant egress controls, signed webhooks for anything inbound, and real client-IP handling so abuse controls act on the true source. Edge DDoS scrubbing from a third party is deliberately not used, to keep a US proxy out of the EU data path; this is reversible under a sustained attack. Source →

Commercial, billing & exit

How is the service priced and billed?
Published per-plan prices in EUR, billed monthly or annually by card through Stripe; add-ons are billed at the same interval. Business plans are quoted and ordered on a written order form. Every charge produces an invoice; the dashboard lists your invoices with PDF download. Source →
Do you accept purchase orders or bank transfer?
Self-serve plans are card-billed. For Business orders, purchase-order references and invoice-based payment can be discussed as part of the quote. Source →
How is VAT handled?
Dutch VAT applies; EU business customers with a valid VAT number are reverse-charged (0%) and account for VAT themselves. Prices are shown excluding or including VAT depending on your customer type. Source →
What are the cancellation and refund terms?
Cancel any time from the dashboard; the service runs to the end of the paid period and does not renew. Consumers and sole traders keep a 14-day right of withdrawal on hosting with a full refund; only a domain registration is non-refundable because the registry commits it the moment it is bought. If we terminate for our own convenience, unused prepaid fees are refunded pro rata. Source →
What is the contractual liability cap?
Fees paid for the affected service in the 12 months before the event, never lower than one billing period, with the usual carve-outs for intent, fraud and rights that cannot be limited. A Business order form may state a negotiated cap. Source →
What is the order of precedence between documents?
A signed order form or plan-specific written agreement first, then the Terms, then the referenced policies (SLA, AUP, Privacy). For the processing of Customer Content personal data the DPA prevails. Source →
How do we leave, and what does it cost?
Nothing. Export files, databases, DNS zones and mail at any time; request a domain’s transfer code and lock removal (provided within five business days, no transfer-away fee); standard stacks mean the site runs anywhere. Leaving is a download, not a negotiation. Source →
Do you help with migration in?
Yes. Assisted migration is free: we move the site, database, DNS and mailboxes with no downtime, on a documented plan. Source →

Not held or not offered

  • ISO/IEC 27001 certification
  • SOC 2 report
  • Independent penetration-test report (published)
  • Cyber-liability insurance certificate (published)
  • Single sign-on (SAML / OIDC) for customer accounts
  • 24/7 staffed human support

These answers are maintained with the platform and reviewed on every change to the security posture, the DPA or the SLA. They describe the service as operated on the review date above; a countersigned copy for your file is available from legal@veldhost.eu.