Security and reliability
Your data: locked down, and always under your control.
Handing your database to someone else is a leap of faith. Here is exactly how we earn it: how we protect your data, how we keep it available, and how you stay in control of it. Instead of badges and promises, here are the facts you can check yourself.
Security or compliance questions? Email team@selfhost.dev.
The right cloud for each job.
Dedicated PostgreSQL, MySQL, Redis and ClickHouse on AWS, with BYOC into your own account. Multi-AZ on all four, PITR on Postgres and MySQL.
Apps on dedicated single-tenant servers, 2 to 16 vCPU, from about $0.02/hr. A fraction of hyperscaler cost.
We put each workload on the cloud that does it best, and handle the ops. You just get their uptime and performance.
How we protect your data
Private by default.
Not exposed by accident.
Single-tenant hardware
Managed instances and project servers run on hardware that is yours alone, not a slice of a multi-tenant cluster you cannot see. No noisy neighbors, no shared surface.
Encrypted in transit and at rest
Connections use TLS in transit, and managed-instance storage is encrypted at rest on EBS with AWS KMS keys. Custom domains get automatic HTTPS too. Your data is protected on the wire and on disk.
Locked down by default
IP whitelisting, delete protection, and public access only if you turn it on. Your database is not on the open internet by accident.
Users, roles, and rotation
On PostgreSQL and MySQL, create read-only, read-write, or admin users per database and rotate a password in one click. New secrets are revealed once, then never stored in plain text. Nobody shares the admin login.
Private networking
Your VPC, your security groups, your region. Managed instances live inside a private network you control, not a shared public endpoint.
Guarded AI access
The MCP server never connects to your databases directly. Credentials are stored locally with owner-only permissions (chmod 600), and destructive operations require explicit confirmation before they run.
Built to stay up
No uptime theater.
Reliability you can point at.
Here is the machinery that keeps you online, and the receipts. A Multi-AZ standby that fails over automatically on every engine, continuous archives that restore to any second on PostgreSQL and MySQL, backup policies that run on the schedule you set, and alerts that reach you first. Then we publish the real, measured uptime, so you can check availability yourself instead of taking a number on faith.
Your data stays yours
Your database lives in your own account.
Not locked inside ours.
The strongest security guarantee is not needing one. It is standard PostgreSQL, MySQL, Redis, and ClickHouse on standard AWS infrastructure, with nothing proprietary between you and the engine. Your data, your dumps, your replication. And with BYOC the instance runs inside your own AWS account, so it stays yours by default, running where it always was, whether you are with us for years or run it in your own account from day one.
- ✓ BYOC into your own AWS account, via access keys or an IAM role
- ✓ Standard engines, exportable with the normal tools, no lock-in
- ✓ Free white-glove migration onto Selfhost.dev, run by a real engineer
Most platforms make leaving expensive on purpose. We do the opposite: prepaid credits you own, no tiers to deprecate, and a database that speaks the standard wire protocol.
Even if you never opened our console again, a BYOC database keeps running in your own account, untouched. That is the point.
Pay-as-you-go either way. Build your exact bill.
Where your data lives
The full list of who touches your data.
No surprises behind the curtain.
These are the third parties that process data on our behalf so Selfhost.dev can run. That is the whole list.
Amazon Web Services (AWS)
Managed database instances and their backups. Your managed PostgreSQL, MySQL, Redis, and ClickHouse run here, in the region you choose.
Hetzner Cloud
Project servers, on dedicated single-tenant machines in EU data centers (Germany and Finland).
Razorpay
Payment processing for credit top-ups. We never see or store your full card details.
Cloudflare
DNS, TLS certificates, and content delivery for the website and custom domains.
Tawk.to
Live chat on the website (desktop only), if you choose to start a conversation.
How we earn your trust
Honesty is part of the security model.
You can choose to keep your database in your own AWS account. With BYOC it runs on infrastructure you own and control, and never leaves it. Most managed providers reserve that for an enterprise or custom-priced plan, the kind that starts around $250 a month and climbs from there, if they offer it at all. We hand it to every account at no extra cost, no enterprise tier required.
Alongside it: standard engines you can export any time, published benchmarks with the methodology and the gaps shown, measured uptime you can check on the status page, and a bill that pauses at a zero balance so nothing runs up in the dark.
And if a compliance box is what is holding you back: we are not SOC 2 or HIPAA certified today, only because the teams we serve have not needed them yet. If yours does, that is a conversation, not a dead end. Tell us what your review requires and we can pursue it.
Frequently Asked Questions
Is Selfhost.dev SOC 2 or HIPAA certified?
Is my data encrypted?
Where is my data stored?
What happens to my data if I stop using Selfhost.dev?
Who can access my database?
Do you have a status page?
Trust you can verify.
Not trust you take on faith.
Security or compliance questions? Email team@selfhost.dev.