EU data centre · engineers in Jelenia Góra Provisioned within 24 h on working days · hello@thebillboys.pl
The Bill BoysInfrastructure
Security

Security and data residency

Our equipment stands in data centres inside the European Union, and EU data residency is the default on every plan we sell: production, backups and the replication target. What follows is a description of the controls we run and the duties we carry. It is deliberately not a list of certifications, because we do not hold any.

Written to be read by your auditor, not by your marketing team

A hand holding an access card against a wall-mounted card reader
Access control at the facility door
Locked mesh cabinets and a caged aisle inside a data hall
Locked cabinets, caged aisle
Row of electrical switchgear cabinets in a plant room
Switchgear, two feeds
EUDefault residency for production, backups and the replication target
1 dayWorking-day target to acknowledge a reported vulnerability
0Shared administrative logins. Every engineer works from a named account
30 daysData kept after a term ends, then deleted, unless you ask sooner
Residency

Where the data sits

Three commitments, written the way we would want them written if we were the ones buying.

EU

Facilities inside the European Union

Every machine we operate for customers is housed in a data centre in the EU, and so is the second site we replicate to. Nothing you store runs on hardware outside the Union. The one exception is the payment step: billing details you enter at checkout are handled by our payment provider under its own notice, which the privacy notice sets out in full.

REQ

Ask for a region when you order

If your policy or your own customers require a specific EU country or a specific pair of sites for the primary and the replica, say so before you pay, in the order notes or by email. We confirm in writing whether we can meet it, and if we cannot we say so before taking the money rather than after.

ASK

Nothing moves without asking you

We do not relocate customer data to another region, another provider or another country because it is cheaper or more convenient for us. A move happens only after a written agreement with you, and that includes copies made for support, debugging or testing.

Controls

Physical and platform controls

What we and the facilities that house our racks actually do. Each line is a practice, not a badge.

Patch panel and switch ports with several uplinks connected
Two uplinks per rack, separate paths
Engineer sliding a line card into a network chassis
Hardware handled by our engineers
Hand attaching a printed label to fibre patch cables in a rack
Every cable and port labelled
DOOR

Access-controlled facilities

The halls that hold our racks are entered with a card and a logged visit, under camera coverage. Our cabinets are locked, and only our own engineers open them or handle the hardware inside.

A/B

Redundant power

Two independent power paths reach each rack, backed by UPS and a diesel generator whose autostart is tested rather than assumed. Dual-supply servers take one feed from each path.

Redundant network paths

More than one upstream carrier and more than one uplink per rack, so a single fibre cut or a single upstream fault degrades capacity instead of ending service. Filtering against volumetric attacks sits at the border.

RAID

Redundant storage in the machine

Customer data lands on NVMe in a RAID set, so a failed drive is a replacement job rather than an incident. RAID protects against a dead drive and nothing else, which is why the backup section below exists.

1:1

Isolated tenancy per customer

Virtual machines get their own kernel, their own storage volumes and their own network segment. Shared hosting accounts run under separate system users with their own PHP process pool and resource limits. Dedicated and private-cloud plans are single-tenant hardware.

PATCH

Hypervisor and managed OS patching

We patch the virtualisation layer, the operating system of managed plans, the hosting panels and our own tooling on a weekly schedule, and sooner when a vulnerability is being exploited. Reboots that cannot be avoided are announced first.

Plainly

What we do not claim

We are a small and young company. We hold no security certification of our own, and writing anything else here would cost you money later, when the certificate you assumed was in place is the one your auditor asks to see.

The data centres that house our equipment do hold their own certifications. We will name the facility and send its current certificates during procurement, under a mutual non-disclosure agreement if you need one. What we will not do is print somebody else's badge on our website and let it read as ours.

If a certification is a hard requirement for your purchase, tell us at the start. It is a better use of your time than discovering it at the contract stage, and we would rather lose the order than win it on a misunderstanding.

The list
  • We are not ISO 27001 certified.
  • We have no SOC 2 report, of either type.
  • We hold no other security or compliance certification, and we display no compliance badges.
  • We publish no measured availability figure. Each plan carries a service target, which is a promise about the future and not a measurement of the past.
  • We run no paid vulnerability bounty.
  • We name no customers and quote nobody, because at our age we would have to invent them.

Everything above is a statement about us, not about the facilities we buy space in. Their certifications are real, and are theirs.

Backups

Backups and recovery

What each plan includes, taken from the same source as the plan pages, so the two cannot drift apart.

An opened hard disk drive showing the platter and the read head

Copies live away from the machine

Backups are written to storage separate from the server that produced them, never only to the disk they are protecting. Off-site copies go to a second data centre in the European Union. The Backup & Object Storage plan adds immutable retention, meaning that for the period you set, an object cannot be altered or deleted, by you, by an attacker holding your keys, or by us.

PlanBackups included
Web Hosting Business Daily, 30 days
Managed WordPress Daily, 30 days
Cloud VPS Pro Weekly snapshots
Backup & Object Storage Immutable, your policy
Dedicated Cloud Server Daily, 14 days
Kubernetes Platform Daily volume snapshots
Enterprise Private Cloud Daily + off-site copy

CDN & Edge Delivery holds no primary data, only cached copies of your origin, so it has no backup line. Any plan can take the daily off-site backup add-on, which keeps 30 days of copies in a second EU data centre.

Asking for a restore

Write to hello@thebillboys.pl with the order reference, what you need back and the point in time you want. A restore is treated as a support request at the severity the situation deserves, and data at risk is the highest one. We restore to a location you choose, so a recovery does not overwrite a live system while you are still deciding.

Restores are tested

A backup nobody has restored is a hope, not a backup. We run a documented restore test every quarter on the backup platform and record the result. Ask and we will tell you when the last one ran.

Keep an independent copy

Keep your own copy of anything you could not rebuild, somewhere that is not us. We say the same in the terms. Our backups are good and we test them, and they are still a single supplier holding a single set of copies. A second, independent copy is the cheapest insurance in this industry.

Access

Encryption and who holds the keys

  • Certificates are issued and renewed automatically for the domains on your environment, and renewal is monitored so that an expiry becomes an alert rather than an outage.
  • Administrative access to your systems runs over encrypted sessions only. Panels and consoles are served over TLS, and plain unencrypted management protocols are not offered.
  • Every engineer has a named account with their own key. There is no shared operations login and no team password anyone could pass along.
  • Access to a customer environment is granted for the work in hand: provisioning, an agreed change, an incident you reported. It is not standing access held by the whole team in case it is needed one day.
  • Administrative actions are logged, and a departing engineer's keys are removed the day the access ends.
  • Encryption of the data inside your application, and of anything you place in object storage, is yours to configure. Tell us what you need and we will help you set it up.
How support requests are handled
Engineer working at a console beside equipment racks in a server room
Shared responsibility

Your side of the line

Hosting is a split job. This is the split as we understand it, so nobody discovers the boundary during an incident.

What we look after

  • The facility, power, network and hardware, including replacing what fails.
  • The virtualisation layer and its patching.
  • The operating system, panel and stack on managed plans.
  • Backups where the plan includes them, and the quarterly restore test.
  • Certificates, monitoring, and the border filtering in front of your service.
  • Telling you when we change something that touches your environment.

What stays with you

  • Your application: its code, its dependencies, its file permissions and how it handles input.
  • Your CMS, its themes and its plugins, on any plan where you administer them. An unpatched plugin is the most common way a hosted site is taken over.
  • Your passwords and SSH keys, and rotating them when somebody leaves.
  • Who you grant access to, at what level, and removing that access when the work ends.
  • Your own copy of important data, kept somewhere that is not us.
  • Your legal duties towards the people whose data you store on the service.

On managed WordPress we apply core and plugin updates on a schedule as part of the plan, which moves that line. On plans with root access it stays with you unless we agree a managed arrangement in writing.

Disclosure

Reporting a vulnerability

If you have found a weakness in our infrastructure, our website or a customer environment we operate, we want to hear it.

Write to us

Send the details to hello@thebillboys.pl with "vulnerability" in the subject. It reaches the same people who run the platform. We do not run a separate reporting address, because a second inbox is a second place for a message to sit unread.

We acknowledge in one working day

You get a human reply within one working day confirming that the report arrived and who is looking at it. If the finding is serious we say so in that first reply rather than going quiet.

We investigate and keep you posted

We reproduce the issue, work out who is affected and tell you what we found, including when we conclude that it is not exploitable. Customers whose environments are affected are told directly.

We fix and report back

You hear what changed and when it shipped. If you would like credit for the finding we are glad to give it, in writing, wherever you would find it useful.

We do not pay for reports

There is no paid bounty programme, and we would rather say that here than let a researcher spend an afternoon on us expecting one. What we offer is a fast, honest answer, credit if you want it, and a reference for your own work.

Please test only what is yours

Test against your own environment, not another customer's. Avoid denial-of-service testing, avoid anything that would read or alter data that is not yours, and give us a chance to fix a finding before it is published. Report in good faith and we will treat you the same way.

Data protection

Processing, agreements and deletion

The contractual half of the same subject, kept short here because the documents themselves are the authority.

We are the processor

Personal data that you or your users place on a hosted environment is processed by us only on your instructions. You remain the controller. What we do with your own data, as a customer of ours, is set out in the privacy notice.

A processing agreement on request

A data-processing agreement under article 28 GDPR is available before or after you order, at no charge. Ask by email and we send it for signature. If your own template must be used instead, send it and we will read it and say what we can sign.

When a service ends

Ask and we hand over a full copy of your data in a usable format, with no exit fee. Data is kept for 30 days after the term ends and is then deleted, or sooner if you ask for early deletion in writing. The full wording is in the terms.

Send us the hard questions

Security review, vendor questionnaire, a clause your legal team will not move on. An engineer answers, and where the answer is no, it will say no.