Security and reliability

Your data: locked down, and always under your control.

Handing your database to someone else is a leap of faith. Here is exactly how we earn it: how we protect your data, how we keep it available, and how you stay in control of it. Instead of badges and promises, here are the facts you can check yourself.

Start free, no card needed

Security or compliance questions? Email team@selfhost.dev.

Powered by proven clouds

The right cloud for each job.

Amazon Web Services (AWS)
Managed databases

Dedicated PostgreSQL, MySQL, Redis and ClickHouse on AWS, with BYOC into your own account. Multi-AZ on all four, PITR on Postgres and MySQL.

Hetzner
Your projects

Apps on dedicated single-tenant servers, 2 to 16 vCPU, from about $0.02/hr. A fraction of hyperscaler cost.

We put each workload on the cloud that does it best, and handle the ops. You just get their uptime and performance.

How we protect your data

Private by default.
Not exposed by accident.

Single-tenant hardware

Managed instances and project servers run on hardware that is yours alone, not a slice of a multi-tenant cluster you cannot see. No noisy neighbors, no shared surface.

Encrypted in transit and at rest

Connections use TLS in transit, and managed-instance storage is encrypted at rest on EBS with AWS KMS keys. Custom domains get automatic HTTPS too. Your data is protected on the wire and on disk.

Locked down by default

IP whitelisting, delete protection, and public access only if you turn it on. Your database is not on the open internet by accident.

Users, roles, and rotation

On PostgreSQL and MySQL, create read-only, read-write, or admin users per database and rotate a password in one click. New secrets are revealed once, then never stored in plain text. Nobody shares the admin login.

Private networking

Your VPC, your security groups, your region. Managed instances live inside a private network you control, not a shared public endpoint.

Guarded AI access

The MCP server never connects to your databases directly. Credentials are stored locally with owner-only permissions (chmod 600), and destructive operations require explicit confirmation before they run.

Built to stay up

No uptime theater.
Reliability you can point at.

Here is the machinery that keeps you online, and the receipts. A Multi-AZ standby that fails over automatically on every engine, continuous archives that restore to any second on PostgreSQL and MySQL, backup policies that run on the schedule you set, and alerts that reach you first. Then we publish the real, measured uptime, so you can check availability yourself instead of taking a number on faith.

+ Multi-AZ automatic failover (all engines) + Point-in-time recovery, restore to any second + Automated backups and snapshots on every engine + Read replicas on Redis + Alerts by email and Slack

Your data stays yours

Your database lives in your own account.
Not locked inside ours.

The strongest security guarantee is not needing one. It is standard PostgreSQL, MySQL, Redis, and ClickHouse on standard AWS infrastructure, with nothing proprietary between you and the engine. Your data, your dumps, your replication. And with BYOC the instance runs inside your own AWS account, so it stays yours by default, running where it always was, whether you are with us for years or run it in your own account from day one.

  • BYOC into your own AWS account, via access keys or an IAM role
  • Standard engines, exportable with the normal tools, no lock-in
  • Free white-glove migration onto Selfhost.dev, run by a real engineer
No lock-in, by construction

Most platforms make leaving expensive on purpose. We do the opposite: prepaid credits you own, no tiers to deprecate, and a database that speaks the standard wire protocol.

Even if you never opened our console again, a BYOC database keeps running in your own account, untouched. That is the point.

Pay-as-you-go either way. Build your exact bill.

Where your data lives

The full list of who touches your data.
No surprises behind the curtain.

These are the third parties that process data on our behalf so Selfhost.dev can run. That is the whole list.

Amazon Web Services (AWS)

Managed database instances and their backups. Your managed PostgreSQL, MySQL, Redis, and ClickHouse run here, in the region you choose.

Hetzner Cloud

Project servers, on dedicated single-tenant machines in EU data centers (Germany and Finland).

Razorpay

Payment processing for credit top-ups. We never see or store your full card details.

Cloudflare

DNS, TLS certificates, and content delivery for the website and custom domains.

Tawk.to

Live chat on the website (desktop only), if you choose to start a conversation.

How we earn your trust

Honesty is part of the security model.

You can choose to keep your database in your own AWS account. With BYOC it runs on infrastructure you own and control, and never leaves it. Most managed providers reserve that for an enterprise or custom-priced plan, the kind that starts around $250 a month and climbs from there, if they offer it at all. We hand it to every account at no extra cost, no enterprise tier required.

Alongside it: standard engines you can export any time, published benchmarks with the methodology and the gaps shown, measured uptime you can check on the status page, and a bill that pauses at a zero balance so nothing runs up in the dark.

And if a compliance box is what is holding you back: we are not SOC 2 or HIPAA certified today, only because the teams we serve have not needed them yet. If yours does, that is a conversation, not a dead end. Tell us what your review requires and we can pursue it.

Frequently Asked Questions

Is Selfhost.dev SOC 2 or HIPAA certified?
No. Selfhost.dev is not SOC 2 or HIPAA certified today, and we do not claim otherwise. If your company gates vendors on those attestations, we are not there yet. Instead, we protect your data with single-tenant instances, encryption in transit, IP whitelisting, credential rotation, Multi-AZ failover on every engine, point-in-time recovery on PostgreSQL and MySQL, automated backups, and BYOC so your data can stay in your own AWS account. For teams weighing the compliance question against control and cost, see our Selfhost.dev vs AWS RDS comparison.
Is my data encrypted?
Connections are encrypted in transit with TLS, and managed instances store your data at rest on encrypted EBS volumes using AWS KMS keys, so backups and snapshots are encrypted too. Your managed databases also sit behind IP whitelisting and are private by default, so they are not exposed to the open internet unless you turn public access on.
Where is my data stored?
Managed databases run on AWS, in the region you pick when you create the instance. Project servers run on dedicated single-tenant machines in EU data centers (Germany and Finland). With BYOC, your managed database runs inside your own AWS account, so the data never leaves it.
What happens to my data if I stop using Selfhost.dev?
It is standard PostgreSQL, MySQL, Redis, and ClickHouse on standard AWS infrastructure, with nothing proprietary in between. You can dump, replicate, and export it with the normal tools at any time. With BYOC the instance never leaves your account in the first place, so even if you stop using us, the database is still yours, running where it always was.
Who can access my database?
Databases are locked down by default: IP whitelisting, delete protection, and public access only if you turn it on. On PostgreSQL and MySQL you create database users with read-only, read-write, or admin roles and rotate their passwords in one click, so nobody has to share a single admin login.
Do you have a status page?
Yes. Our public status page shows real, measured uptime for the console, API, and website, so you can check availability yourself rather than take a marketing number on faith.

Trust you can verify.
Not trust you take on faith.

Start free, no card needed

Security or compliance questions? Email team@selfhost.dev.