Trust

Where your budget actually lives

Everything on this page is checkable. Where a limit exists, it is stated with the number beside it rather than a reassuring phrase.

The short version

ApplicationHetzner, Falkenstein, Germany
DatabaseNeon Postgres, Frankfurt (eu-central-1)
In frontCloudflare. DNS, WAF and proxy only, not a host
OwnershipEU-owned infrastructure throughout
IsolationRow-level security on every tenant table, audited against the live database on each deploy
BackupsNightly logical export, 03:15 UTC. The restore path is rehearsed, not assumed
Point-in-time recoverySix hours. See the limit stated in full on Security

What we do not claim

This section exists because its absence is where vendors quietly overstate. None of the following is true of itbudgit today, and none of it appears anywhere else on this site:

  • No SOC 2 and no ISO 27001. Neither is held, and neither is in progress. ISO 27001 has been assessed and ruled out as a single-person initiative
  • No penetration test has been performed.
  • No uptime SLA is offered. One will not appear until it can be measured and honoured
  • No free trial. Plans are annual, and what you see on the pricing page is what is sold

itbudgit is run by one person. That is a real constraint and it is better stated than discovered.

The rest

  • Security. Architecture, isolation, backups, and the recovery limit in full
  • GDPR. Roles, lawful basis, your rights, and how erasure actually runs
  • Sub-processors. Every third party that touches the service
  • DPA. The data processing agreement
  • Privacy · Terms · Cookies

Security & compliance: Trust · Security · GDPR · Sub-processors · DPA · Privacy · Terms · Cookies

Questions a page here does not answer: get in touch.