Eza Cloud security
Your app data stays in Kenya
All customer data is stored and processed in Kenya. Eza Cloud runs apps in isolated sandboxes, encrypts data in transit and at rest, and provides a DPA written for Kenya’s Data Protection Act, 2019.
- Data in Kenya
- 2FA for Owners
- Daily backups
- 99.5% uptime
Service facts
- Data location
- Stored and processed in Kenya
- Two-factor sign-in
- Required for Owners and Admins
- Database backups
- Daily, on every plan
- Uptime commitment
- 99.5% each month
- DPA
- Kenya’s Data Protection Act, 2019
All customer data is stored and processed in Kenya
Your app data, managed database data, deployment data and account data are stored and processed in Kenya.
Eza Cloud is available to customers in Kenya at launch.
The DPA is accepted at signup and is publicly available before you pay.
Read the Data Processing AgreementEach app runs in its own sandbox
Every Eza Cloud app runs in its own sandbox with its own kernel.
One customer app cannot access another customer app through the Eza runtime.
Use separate organisations, projects and environments to separate client work, staging and production.
Owners and Admins use two-factor sign-in
Two-factor sign-in is required for every organisation Owner and Admin.
Members and Viewers can enable two-factor sign-in for their own accounts.
Eza accounts require a verified email address and phone number.
Data is encrypted in transit and at rest
Eza encrypts customer data in transit and at rest.
Environment variables use envelope encryption at rest.
Runtime secrets are injected when your app starts. They do not enter the build unless you mark them as build-time variables.
Secret values stay hidden in the dashboard until you reveal them. Eza records each reveal.
Read environment variable securityDaily backups for every managed database
Every managed database on every plan receives daily backups.
PostgreSQL and MongoDB-compatible databases use a daily base backup with continuous log archiving.
MySQL uses a daily full backup with binlog shipping.
Redis-compatible databases use daily snapshots with append-only files.
Database backup retention
| Database | Backup method | Restore window |
|---|---|---|
| PostgreSQL | Daily base backup and continuous log archiving | 7 days, 14 days on Pro |
| MongoDB-compatible | Daily base backup and continuous log archiving | 7 days, 14 days on Pro |
| MySQL | Daily full backup and binlog shipping | 7 days |
| Redis-compatible | Daily snapshot and append-only file | Snapshot restore only |
Backups remain available for 7 days on Hobby and Starter, and 14 days on Pro.
Self-run MongoDB is not a managed database. Eza creates daily volume snapshots kept for 7 days.
Database backups include off-site copies in Kenya. This statement does not apply to Eza Object Storage.
Read database backup details99.5% monthly uptime commitment
Eza Cloud has a public uptime commitment of 99.5% each calendar month.
The commitment covers eligible apps with two or more replicas.
Beta features and add-ons are not covered by uptime credits.
Uptime credits
| Monthly uptime | Credit |
|---|---|
| Below 99.5% | 10% of monthly hosting plan fee |
| Below 99.0% | 25% of monthly hosting plan fee |
| Below 95.0% | 50% of monthly hosting plan fee |
The credit applies automatically to your account balance.
Credits apply to the hosting plan fee. They do not apply to PayEdge, storage packs or other add-ons.
Read the SLACheck Eza service status
The public status page is hosted outside Eza Cloud infrastructure.
It shows current component status, incident history, scheduled maintenance and 90-day uptime history.
Components:
- Dashboard and API
- Builds and deployments
- App runtime and routing
- Managed databases
- Object storage
- PayEdge
- Transactional email
Scheduled maintenance has a window
Planned maintenance may run on Tuesday from 02:00 to 04:00 EAT.
Eza gives at least 48 hours’ notice before planned maintenance.
Planned maintenance may total no more than 4 hours in a calendar month.
Report a security issue
Email security@eza.co.ke with details of a suspected vulnerability or security issue.
Do not include secrets, full database exports or customer personal data in the first email.
Eza publishes security contact details at /.well-known/security.txt.
Email security@eza.co.keSend privacy requests by email
For account, billing and support data held by Eza, email privacy@eza.co.ke.
For personal data inside an app you host on Eza, contact the app owner first. That customer is the data controller for their app data.
Eza acts as a processor for customer-hosted data and helps customers respond to valid data requests.
Email privacy@eza.co.keSecurity incidents need clear communication
Eza uses the public status page for platform-wide service incidents.
Affected customers receive direct communication when an incident affects their Eza account or customer data.
Read the DPA before you sign up
The Eza Data Processing Agreement is written for Kenya’s Data Protection Act, 2019.
You can read the DPA before creating an account.
After signup, your organisation can download a signed copy from the dashboard.
Read the DPABeta features are supported
Beta features are included and supported.
They are not covered by Eza uptime credits.
At launch, Beta applies to:
- Docker Compose
- MySQL
- MongoDB-compatible databases
- PayEdge
- Transactional email
Security FAQ
Security questions
Something else? support@eza.co.ke
Where is my Eza Cloud data stored?
All customer data is stored and processed in Kenya. This includes app data, managed database data, deployment data and account data.
Does Eza require two-factor sign-in?
Yes, Owners and Admins must use two-factor sign-in. Members and Viewers can enable it for their own accounts.
How often are managed databases backed up?
Every managed database receives daily backups on every plan. PostgreSQL and MongoDB-compatible databases also use continuous log archiving, while MySQL uses binlog shipping.
How long are backups kept?
Backups are kept for 7 days on Hobby and Starter, and 14 days on Pro. PostgreSQL and MongoDB-compatible point-in-time recovery follows the same window.
Does Eza back up self-run MongoDB?
Eza creates daily volume snapshots for MongoDB deployed from the template. Those snapshots are kept for 7 days. Self-run MongoDB is not a managed database.
What is Eza’s uptime commitment?
Eza Cloud has a 99.5% monthly uptime commitment for eligible apps with two or more replicas. Automatic credits apply when the monthly commitment is missed.
Are Beta features included in uptime credits?
No. Beta features are included and supported, but they are not covered by uptime credits.
How can I report a security issue?
Email security@eza.co.ke. Do not send secrets, full database exports or customer personal data in the first report.
Read the security details before you deploy
Review the DPA, SLA and public status page. Then deploy your app from Git and pay in KES by M-Pesa.
