ReadyCMS 3.0.63 is live. · Read the changelog

ReadyCMS Trust & Security

ReadyCMS – Trust & Security


Last updated: 14 May 2026


This page describes how ReadyCMS AB protects the data you entrust to us. It is a plain-language summary; the binding commitments are set out in our [Terms of Service], [Data Processing Agreement], and [Privacy Policy].

Where your data lives

All customer data on the ReadyCMS platform is stored on servers in Germany, operated by Hetzner Online GmbH. Production and backups are both held in Germany. Hetzner's data center facilities are ISO 27001-certified.

We also run edge infrastructure (VPN, monitoring) at Hetzner locations in Helsinki and Ashburn. Customer personal data is not processed at those locations.

A complete list of every third party that may handle customer data — and where they are based — is published at [Sub-processors].

How data moves

  • In transit on the public internet: TLS 1.3 with AES-256-GCM is enforced at every public endpoint. Cloudflare provides an outer TLS termination, and we run an inner TLS hop between Cloudflare and our origin servers.
  • -Between our backups and the off-site target: JetBackup encrypts backup data before it leaves the origin server and decrypts it at the storage target. The off-site target itself (Hetzner Storage Box) does not provide encryption at rest, so we rely on encrypted transfer and access controls rather than storage-level encryption.
  • Inside the same host: Traffic between processes on the same Linux host is unencrypted, which is the industry norm for localhost loopback.

Encryption at rest

We are direct about this, so you can make informed decisions:

  • We do not currently apply disk-level encryption (LUKS) or database-level encryption (MySQL TDE) to production storage. The threat model that disk-level encryption mitigates — physical theft of disks from the data center — is, in our assessment, outweighed by the operational complexity it adds in a single-operator environment. We instead rely on Hetzner's physical security controls and data center operating practices.
  • Backups are encrypted in transit, but the storage target itself is unencrypted at rest. Customers requiring end-to-end encryption at rest can encrypt files at the application layer before uploading; the platform does not interfere with that.
  • This posture is documented and reviewed at least annually.

Identity and access control

  • SSH to production: key-only authentication; password authentication disabled; Google Authenticator second factor required.
  • WHM / cPanel: two-factor authentication required for all administrative accounts.
  • Cloudflare: two-factor authentication required.
  • ReadyCMS admin dashboard: Two-factor authentication is available to all customers and required for administrative roles.
  • Password policy: length, complexity, and history requirements aligned with current OWASP recommendations.

Application security

  • Cloudflare WAF and Security Rules in front of every customer-facing endpoint.
  • CSF (ConfigServer Security & Firewall) on origin hosts.
  • Imunify360 for malware detection and remediation on hosted accounts.
  • cPHulk brute-force protection for control-panel logins.
  • Built-in XSS and injection protections in the ReadyCMS application layer.
  • Internal code review for changes to authentication, authorization, billing, and storage code paths.

Backups and recoverability

  • Daily backups via JetBackup, written to a Hetzner Storage Box in Germany.
  • Hetzner-level snapshots as a second layer.
  • Backups are retained for 30 days under standard rotation; customers on enterprise plans can request longer retention by agreement.
  • No point-in-time recovery at present: MySQL binary logging is not enabled. The smallest recoverable unit is the most recent daily snapshot.

We test restore procedures regularly. The most recent test was conducted as part of the May 2026 recovery exercise.

Monitoring and incident response

  • Service health, system logs, and security alerts are routed to our internal monitoring stack.
  • Anomalies are reviewed promptly during Business Hours; out-of-hours pages are routed to the on-call founder.
  • A documented incident-response procedure governs detection, triage, containment, and customer notification. The procedure addresses the timelines and content requirements set out in Articles 33 and 34 of the GDPR.
  • Customers are notified of personal-data breaches in accordance with Annex II of the [DPA](/legal/dpa/) — without undue delay after we become aware, and never later than 72 hours where the breach is likely to result in a risk to the rights and freedoms of natural persons.

Vulnerability management

  • Operating systems and application packages are patched on a regular cadence; critical security patches are applied within 7 days of vendor release, sooner if the vulnerability is actively exploited.
  • We monitor CVE feeds, vendor advisories, and the EU Vulnerability Database for software in our stack.
  • Customer-reported security issues should be sent to support@readycms.io. We acknowledge within one Business Day.

Compliance and certifications

ReadyCMS AB is a Swedish company subject to the GDPR, the Swedish Data Protection Act (SFS 2018:218), the Swedish Bookkeeping Act, and the Swedish Electronic Communications Act (LEK 2022:482).

We do not currently hold ISO 27001 or SOC 2 certification, and these are not on our near-term roadmap. We do not claim to.

Where customer contracts require specific compliance attestations beyond what we publish here, please contact privacy@readycms.io to discuss.

Data subject and regulator requests

  • We assist customers in responding to data subject requests (access, rectification, erasure, restriction, portability, and objection) as set out in the DPA.
  • Government and law enforcement requests for customer data are reviewed for legal validity. Where permitted by law, we notify the affected customer before responding.

Business continuity

The ReadyCMS service primarily depends on the Hetzner infrastructure in Germany. In the event of a regional Hetzner outage, recovery time depends on Hetzner's own restoration timeline. We do not currently operate hot standby in a second region; this is an open item on our roadmap.

Contact

  • Security and breach reporting: support@readycms.io
  • Privacy and data protection: privacy@readycms.io
  • General: info@readycms.io

Document history

 Date  Change 
 
 
 2026-05-14 Initial publication.