Data Protection at Sadeem Cloud
How we host, isolate, encrypt, back up and recover the data you trust us with. This page describes the technical measures behind our managed hosting platform.
On this page
Where your data lives
Sadeem Cloud runs infrastructure in data centers located inside the Kingdom of Saudi Arabia, in Europe and in the wider Middle East. The region of your instance is agreed with you and recorded in your service order.
Clients who need their data to remain inside the Kingdom can be provisioned on our Saudi region. We never move an instance to a different region without prior written notice.
Our infrastructure partners are established providers that operate certified facilities: OVH, Hetzner, Oracle Cloud, Contabo and Amazon Web Services. Network delivery and edge protection run through Cloudflare.
Backups
We keep 17 full backups of every customer database, on a rolling schedule:
| Type | Count | Covers |
|---|---|---|
| Daily backups | 14 | The last 14 days |
| Weekly backups | 2 | The previous two weeks |
| Monthly backup | 1 | The previous month |
- Backups are replicated across at least two separate data centers, located on at least two different continents, for redundancy and availability.
- You can download a manual backup of your live data at any time from the control panel.
- You can ask our support team to restore any retained backup onto your live database or onto a staging instance.
Disaster recovery
In the unlikely event of a complete data center outage, which has never occurred so far, we operate a disaster recovery plan with the following objectives:
Recovery point objective: 24 hours
In the worst case you could lose up to 24 hours of work, because we would restore from the most recent daily backup.
Recovery time objective: 24 hours
Subscriptions are restored and back in service within 24 hours of the incident being declared.
How this is achieved
- Daily backups are actively monitored and replicated across multiple geographic locations.
- Restoring from the previous day's backup can be completed within a few hours.
- Recovery procedures are documented and rehearsed rather than improvised during an incident.
Database isolation
- Every customer's data is stored in a dedicated, isolated database. We do not share a database between clients.
- Strict access control rules enforce complete isolation between customer databases running on the same cluster.
- Cross database access is not permitted, by configuration and not only by policy.
Staff access
- Our support team may sign in to your instance to reproduce and resolve a reported issue.
- They use their own internal credentials. They do not have your password and cannot read it.
- Every action taken by a staff member is recorded in a separate audit trail.
- Our helpdesk accesses only the files and settings needed to diagnose and fix the issue in front of them.
System security
- All Sadeem Cloud servers run hardened Linux distributions with security patches applied regularly.
- Remote server access is limited to a small number of trusted Sadeem engineers.
- Access uses encrypted SSH key pairs, from machines with full disk encryption.
- Administrative access is reviewed when a team member's role changes.
Physical security
Our servers are hosted in facilities that meet the following criteria:
- Restricted perimeter access, limited to authorised personnel only.
- Biometric or badge based access control.
- Continuous CCTV surveillance of all critical areas.
- On site security personnel available around the clock.
- Redundant power and cooling, with backup generators.
Encryption
Customer data is encrypted in transit and protected at rest:
- 256-bit SSL encryption over HTTPS protects all traffic between your users and your instance.
- Internal communication between our servers is encrypted end to end.
- Our servers are monitored and patched against known SSL and TLS vulnerabilities.
- All certificates use 2048-bit keys with full SHA-2 chains, and achieve an A+ rating on the major SSL testing tools.
Network defense
- Our infrastructure providers operate networks sized to absorb very large distributed denial of service attacks.
- Attack traffic is detected and diverted at the edge of the network, before it reaches your instance.
- Firewalls and intrusion prevention systems on our servers detect and block threats such as brute force password attempts.
- Database administrators can configure login attempt limits and cooldown periods for their own users.
Payment card safety
- We do not store credit card information on our systems.
- Payment details are transmitted directly between you and payment providers that comply with PCI DSS.
- Our staff never see, and never ask for, your full card number.
Data ownership and exit
Your data belongs to you. We claim no ownership over it and we never use it for our own purposes.
- You can export a full backup at any time while your subscription is active.
- After termination, your data remains available for export for 30 days.
- After that window, the instance and all of its backups are permanently deleted and cannot be recovered.
How we handle personal data, and the rights you have over it, are described in our Privacy Policy. The commercial terms of the service are in our Terms and Conditions.
Security questions, or a request for our data processing agreement: [email protected]
Contact
Not sure where to start?
Tell us what you need and our team will come back to you within 24 hours with a clear plan and a transparent quote. No obligation.