Isolated by design. Reviewed before deploy. Hosted in Norway.
Managed hosting only earns the name if the boring parts are genuinely handled. This page describes how CloudContainer is built, what we take responsibility for, and what remains yours.
Platform
How the platform is protected
Isolation by default
Each customer gets a separate CloudContainer with its own compute, memory and disk. Applications, databases and storage from different customers do not share a runtime.
Norwegian infrastructure
CloudContainer compute runs on Norwegian infrastructure. AI review requests are analysed by an external model provider — see below for what that means in practice.
Encryption
TLS 1.2+ on every public endpoint with certificates issued and renewed automatically. Data at rest is encrypted at the volume level; secrets are encrypted individually.
Secret handling
Environment secrets are encrypted at rest, injected at runtime, masked in the interface and excluded from build logs. Access is scoped to the environment that needs them.
Outbound-only management
cc-agent initiates its own authenticated connection to the control plane. There is no inbound management port on your environment to find or attack.
Backups you can actually restore
The CloudContainer is backed up daily and restore points are stored separately from the production environment. Restoring is a first-class operation, not a support ticket.
Patched without you asking
Operating system and platform components are updated inside the maintenance window you choose. Critical fixes can be applied out of band with notice.
Continuous operational review
AI Operations watches errors, restarts, latency and resource pressure, and surfaces the deployment most likely responsible for a change in behaviour.
AI Security Review
The last check before anything goes live
A large share of production incidents in small teams come from a small set of mistakes: a key committed by accident, a dependency with a known advisory, a debug flag left on. CloudContainer looks for exactly those, on the change you are about to ship.
Findings arrive as an explanation and a concrete instruction. If you build with a coding agent, paste it back and let the agent fix it.
Being straight about scope: this is an automated review that catches common, high-frequency problems. It is not a penetration test, not a formal audit, and not a substitute for your own security work.
what the review looks for
Secrets and API keys
Credentials committed to the repository, in code, config or environment files.
Vulnerable dependencies
Known advisories affecting packages introduced or upgraded in the change.
Risky code changes
New outbound network calls, privileged operations, weakened authentication or authorisation paths.
Configuration drift
Debug flags, permissive CORS, disabled TLS verification and similar settings that should not reach production.
Your data
Plain answers about who holds what
If any of these answers would fail your procurement review, tell us before you sign up rather than after.
Where your source code lives
Your GitHub organisation. CloudContainer reads it to build; it never becomes the owner.
Who can reach your database
Your application, and anyone you give the credentials to. Credentials are visible and exportable to you.
What we can see
Platform telemetry, build output and application logs required to operate and support the service.
What happens on cancellation
The environment is suspended, then deleted after a notice period, and backups are purged on the same schedule. Export your data before that point.
Compliance
Where we actually stand
We would rather tell you what is true today than list badges we have not earned.
- GDPR. CloudContainer acts as data processor for the personal data your application stores. A standard data processing agreement is available and is part of the terms.
- Data location. CloudContainer compute runs on Norwegian infrastructure. Our subprocessor list, including the AI model provider, is available on request and before signature.
- AI processing. AI Security Review and AI Operations send code diffs and log excerpts to an external model provider for analysis. Those requests leave your environment. Ask us for the current provider and terms before relying on this in a regulated context.
- ISO 27001 / SOC 2. Not certified today. Our internal controls are built against those frameworks and certification is on the roadmap; we will not claim it before it exists.
- Uptime commitments. We do not offer a contractual uptime SLA yet. Availability is published on the status page, and the architecture is designed to keep the control plane out of your application's request path.
Responsible disclosure
If you believe you have found a vulnerability in CloudContainer, email [email protected] with enough detail to reproduce it. We acknowledge within two business days and keep you updated until it is resolved.
Please do not test against other customers' environments, and give us a reasonable window before publishing. We will not pursue legal action against good faith research that follows those two rules.
Incidents
Platform incidents are posted to the status page while they are happening, not after. Incidents affecting the confidentiality or integrity of customer data are notified directly and without undue delay.
View status pageNeed a security review before you buy?
We will answer a questionnaire, sign a DPA, and talk to your security team. That is a normal part of selling to serious companies.
