Security & compliance
Compliance & Security Summary
A summary of Hostaan Oy's security principles, practices and regulatory compliance - written to be shared with customers without a separate NDA.
1. Introduction
Hostaan Oy maintains a lightweight security management model (ISMS-Lite) designed to ensure the reliability of our services, clear risk management, and continuous improvement of our security posture. The model is based on the core principles of the ISO/IEC 27001 standard, adapted to the scale and structure of an SME.
Our operations are centered on Finnish SME customers, and on running e-commerce, digital services and websites.
2. Cloud infrastructure and data centers
Hostaan relies on two independent, externally audited data center providers (UpCloud & Hetzner). The infrastructure they provide meets the following recognised certifications and audits:
UpCloud:
– ISO 27001 (Information Security Management System)
– SOC 2 Type II
– PCI DSS
– ISO 22301 (Business Continuity)
– ISO 9001 (Quality Management)
Hetzner:
– ISO 27001
– Operations compliant with EU GDPR
– Regular external audits
Our Finnish customers' services are, by default, located in Finland, with failover arrangements carried out within the EU under GDPR. Read more about our server environment.
3. Risk management and security practices
Hostaan monitors and develops its operations according to the lightweight ISMS model:
– regular risk assessments
– clearly defined security and privacy responsibilities
– planned management of software updates and vulnerabilities
– monitoring and logging practices scoped to our operations
– clear procedures for incident response
Operations follow the principle of least privilege, trusted authentication, and a managed access-rights lifecycle. Read more about our security and backups.
4. Business continuity
Hostaan maintains a business continuity model (BCP) and a disaster recovery process (DRP) to keep services running. This includes:
– planned backups
– geographic distribution within the EU
– management of service outages
– clearly defined recovery responsibilities
This ensures our services stay available even during disruptions.
5. Data protection and GDPR
Hostaan operates in accordance with the EU General Data Protection Regulation (GDPR) and maintains up-to-date data protection documentation:
– Data Processing Agreement (DPA)
– Privacy Policy
– Terms of Service
– Digital Services Act documentation
– Sub-processor list (UpCloud, Hetzner and others)
All documents are available on our website.
6. Staff competence and processes
Our staff work under strict security practices, including:
– regular security training
– confidentiality obligations
– clear procedures for incident situations
– controlled access to technical management systems
In a small organisation, responsibilities are clearly assigned and their enforcement is supervised.
7. Commitment to continuous improvement
Hostaan actively tracks its cloud providers' audits, updates its security practices annually, and carries out lightweight internal reviews to ensure ongoing improvement.
Our goal is to offer a clear, transparent security model realistic for an SME - one that is trustworthy and well documented.
Summary
This Compliance & Security Summary gives customers an overall picture of Hostaan's security principles, practices and regulatory compliance. It does not include security-sensitive technical detail, and is therefore intended to be shared without a separate NDA.
More detailed ISMS-Lite documentation and technical detail are available to customers or authorities on a confidential basis under a separate agreement. Contact us at tuki@hostaan.fi.