Security & compliance

Compliance & Security Summary

A summary of Hostaan Oy's security principles, practices and regulatory compliance - written to be shared with customers without a separate NDA.

Published 23 Sep 2026

1. Introduction

Hostaan Oy maintains a lightweight security management model (ISMS-Lite) designed to ensure the reliability of our services, clear risk management, and continuous improvement of our security posture. The model is based on the core principles of the ISO/IEC 27001 standard, adapted to the scale and structure of an SME.

Our operations are centered on Finnish SME customers, and on running e-commerce, digital services and websites.

2. Cloud infrastructure and data centers

Hostaan relies on two independent, externally audited data center providers (UpCloud & Hetzner). The infrastructure they provide meets the following recognised certifications and audits:

UpCloud:
– ISO 27001 (Information Security Management System)
– SOC 2 Type II
– PCI DSS
– ISO 22301 (Business Continuity)
– ISO 9001 (Quality Management)

Hetzner:
– ISO 27001
– Operations compliant with EU GDPR
– Regular external audits

Our Finnish customers' services are, by default, located in Finland, with failover arrangements carried out within the EU under GDPR. Read more about our server environment.

3. Risk management and security practices

Hostaan monitors and develops its operations according to the lightweight ISMS model:
– regular risk assessments
– clearly defined security and privacy responsibilities
– planned management of software updates and vulnerabilities
– monitoring and logging practices scoped to our operations
– clear procedures for incident response

Operations follow the principle of least privilege, trusted authentication, and a managed access-rights lifecycle. Read more about our security and backups.

4. Business continuity

Hostaan maintains a business continuity model (BCP) and a disaster recovery process (DRP) to keep services running. This includes:
– planned backups
– geographic distribution within the EU
– management of service outages
– clearly defined recovery responsibilities

This ensures our services stay available even during disruptions.

5. Data protection and GDPR

Hostaan operates in accordance with the EU General Data Protection Regulation (GDPR) and maintains up-to-date data protection documentation:
– Data Processing Agreement (DPA)
– Privacy Policy
– Terms of Service
– Digital Services Act documentation
– Sub-processor list (UpCloud, Hetzner and others)

All documents are available on our website.

6. Staff competence and processes

Our staff work under strict security practices, including:
– regular security training
– confidentiality obligations
– clear procedures for incident situations
– controlled access to technical management systems

In a small organisation, responsibilities are clearly assigned and their enforcement is supervised.

7. Commitment to continuous improvement

Hostaan actively tracks its cloud providers' audits, updates its security practices annually, and carries out lightweight internal reviews to ensure ongoing improvement.

Our goal is to offer a clear, transparent security model realistic for an SME - one that is trustworthy and well documented.

Summary

This Compliance & Security Summary gives customers an overall picture of Hostaan's security principles, practices and regulatory compliance. It does not include security-sensitive technical detail, and is therefore intended to be shared without a separate NDA.

More detailed ISMS-Lite documentation and technical detail are available to customers or authorities on a confidential basis under a separate agreement. Contact us at tuki@hostaan.fi.

See also