Skip to content
Infrastructure

What we run on

Certified data centres inside the EU, hardware that is ours rather than rented by the hour, and a short list of companies whose products we were happy to build on.

42U
Dedicated machines, not rented hours
HelsinkiFalkensteinNurembergAmsterdamPiraeus

Where your data lives

Five sites, all inside the EU. Your machines run in one of three clusters, and their backups always land somewhere else: object storage in Amsterdam, and our own hardware in Piraeus. A complete set therefore exists outside the hosting provider’s estate, on machines only we control.

  • Helsinki, Finland

    Hypervisor cluster · Object storage · Backups

  • Falkenstein, Germany

    Hypervisor cluster · Backups

  • Nuremberg, Germany

    Hypervisor cluster

  • Amsterdam, Netherlands

    Backups

  • Piraeus, Greece

    Backups

Where we answer from

Name resolution and static assets are deliberately not in one place. A visitor in Sydney should not wait for Frankfurt to answer, so they do not — which does mean cached public files are served from outside the EU. Nothing a client would call their data leaves the five sites above.

7 authoritative nameservers 30 CDN edge locations

Our data centres are certified

The facilities your machines sit in are audited every year against the standards below, by independent bodies rather than by their own staff. It is the part of a hosting arrangement that is easiest to claim and hardest to fake, so it is worth naming.

  • ISO/IEC 27001:2022

    Information security management

    The current edition, covering the infrastructure, operation and support of the data centre parks — with no Annex A exclusions.

  • BSI C5 Type 2

    German federal cloud security standard

    Type 2 means the controls were tested for operating effectiveness over a period, not just assessed on design.

  • NIS-2 / KRITIS

    Operator of critical services

    Classified as critical infrastructure in Germany and certified under §8a BSIG.

  • TÜV Rheinland

    Audited technical and organisational measures

    The independent audit a data processing agreement leans on when it refers to appropriate measures.

  • ISO 14001 · EMAS

    Environmental management

    The German sites run on renewable electricity at an average PUE of 1.13.

The facilities are certified. We are working on ours.

Lambda Twelve is currently working towards ISO/IEC 27001 certification. The certificates above cover the facilities our machines sit in; ours will cover how we operate what runs on them.

The stack

Virtualisation is KVM under Proxmox VE, clustered across three sites. Backups always land at a different site from the one the machine runs on. The application stack is Apache, PHP and MariaDB or PostgreSQL depending on what the application wants.

These are choices, not commitments. If a better option appears we will take it, and the rest of this site will not need rewriting.

Sub-processors

Hetzner Online GmbH operates the data centre parks and processes data on our behalf, and is named in our data processing agreement. Backblaze holds a further copy of the backups in S3-compatible object storage. CDNsun caches and serves public static assets from their edge locations. Stripe will handle card payments and eLorus will issue invoices once those are live. Any other sub-processor will be listed here, and in the privacy policy, before it touches client data.

Tell us what you are trying to run.

Describe the workload or the system you have in mind and we will tell you what it needs, what it costs, and whether we are the right people for it.