Skip to content

Eza Cloud security

Your app data stays in Kenya

All customer data is stored and processed in Kenya. Eza Cloud runs apps in isolated sandboxes, encrypts data in transit and at rest, and provides a DPA written for Kenya’s Data Protection Act, 2019.

  • Data in Kenya
  • 2FA for Owners
  • Daily backups
  • 99.5% uptime

Service facts

Data location
Stored and processed in Kenya
Two-factor sign-in
Required for Owners and Admins
Database backups
Daily, on every plan
Uptime commitment
99.5% each month
DPA
Kenya’s Data Protection Act, 2019

All customer data is stored and processed in Kenya

Your app data, managed database data, deployment data and account data are stored and processed in Kenya.

Eza Cloud is available to customers in Kenya at launch.

The DPA is accepted at signup and is publicly available before you pay.

Read the Data Processing Agreement

Each app runs in its own sandbox

Every Eza Cloud app runs in its own sandbox with its own kernel.

One customer app cannot access another customer app through the Eza runtime.

Use separate organisations, projects and environments to separate client work, staging and production.

Owners and Admins use two-factor sign-in

Two-factor sign-in is required for every organisation Owner and Admin.

Members and Viewers can enable two-factor sign-in for their own accounts.

Eza accounts require a verified email address and phone number.

Data is encrypted in transit and at rest

Eza encrypts customer data in transit and at rest.

Environment variables use envelope encryption at rest.

Runtime secrets are injected when your app starts. They do not enter the build unless you mark them as build-time variables.

Secret values stay hidden in the dashboard until you reveal them. Eza records each reveal.

Read environment variable security

Daily backups for every managed database

Every managed database on every plan receives daily backups.

PostgreSQL and MongoDB-compatible databases use a daily base backup with continuous log archiving.

MySQL uses a daily full backup with binlog shipping.

Redis-compatible databases use daily snapshots with append-only files.

Database backup retention

DatabaseBackup methodRestore window
PostgreSQLDaily base backup and continuous log archiving7 days, 14 days on Pro
MongoDB-compatibleDaily base backup and continuous log archiving7 days, 14 days on Pro
MySQLDaily full backup and binlog shipping7 days
Redis-compatibleDaily snapshot and append-only fileSnapshot restore only

Backups remain available for 7 days on Hobby and Starter, and 14 days on Pro.

Self-run MongoDB is not a managed database. Eza creates daily volume snapshots kept for 7 days.

Database backups include off-site copies in Kenya. This statement does not apply to Eza Object Storage.

Read database backup details

99.5% monthly uptime commitment

Eza Cloud has a public uptime commitment of 99.5% each calendar month.

The commitment covers eligible apps with two or more replicas.

Beta features and add-ons are not covered by uptime credits.

Uptime credits

Monthly uptimeCredit
Below 99.5%10% of monthly hosting plan fee
Below 99.0%25% of monthly hosting plan fee
Below 95.0%50% of monthly hosting plan fee

The credit applies automatically to your account balance.

Credits apply to the hosting plan fee. They do not apply to PayEdge, storage packs or other add-ons.

Read the SLA

Check Eza service status

The public status page is hosted outside Eza Cloud infrastructure.

It shows current component status, incident history, scheduled maintenance and 90-day uptime history.

Components:

  • Dashboard and API
  • Builds and deployments
  • App runtime and routing
  • Managed databases
  • Object storage
  • PayEdge
  • Transactional email

Scheduled maintenance has a window

Planned maintenance may run on Tuesday from 02:00 to 04:00 EAT.

Eza gives at least 48 hours’ notice before planned maintenance.

Planned maintenance may total no more than 4 hours in a calendar month.

Report a security issue

Email security@eza.co.ke with details of a suspected vulnerability or security issue.

Do not include secrets, full database exports or customer personal data in the first email.

Eza publishes security contact details at /.well-known/security.txt.

Email security@eza.co.ke

Send privacy requests by email

For account, billing and support data held by Eza, email privacy@eza.co.ke.

For personal data inside an app you host on Eza, contact the app owner first. That customer is the data controller for their app data.

Eza acts as a processor for customer-hosted data and helps customers respond to valid data requests.

Email privacy@eza.co.ke

Security incidents need clear communication

Eza uses the public status page for platform-wide service incidents.

Affected customers receive direct communication when an incident affects their Eza account or customer data.

Read the DPA before you sign up

The Eza Data Processing Agreement is written for Kenya’s Data Protection Act, 2019.

You can read the DPA before creating an account.

After signup, your organisation can download a signed copy from the dashboard.

Read the DPA

Beta features are supported

Beta features are included and supported.

They are not covered by Eza uptime credits.

At launch, Beta applies to:

  • Docker Compose
  • MySQL
  • MongoDB-compatible databases
  • PayEdge
  • Transactional email

Security FAQ

Security questions

Something else? support@eza.co.ke

Where is my Eza Cloud data stored?

All customer data is stored and processed in Kenya. This includes app data, managed database data, deployment data and account data.

Does Eza require two-factor sign-in?

Yes, Owners and Admins must use two-factor sign-in. Members and Viewers can enable it for their own accounts.

How often are managed databases backed up?

Every managed database receives daily backups on every plan. PostgreSQL and MongoDB-compatible databases also use continuous log archiving, while MySQL uses binlog shipping.

How long are backups kept?

Backups are kept for 7 days on Hobby and Starter, and 14 days on Pro. PostgreSQL and MongoDB-compatible point-in-time recovery follows the same window.

Does Eza back up self-run MongoDB?

Eza creates daily volume snapshots for MongoDB deployed from the template. Those snapshots are kept for 7 days. Self-run MongoDB is not a managed database.

What is Eza’s uptime commitment?

Eza Cloud has a 99.5% monthly uptime commitment for eligible apps with two or more replicas. Automatic credits apply when the monthly commitment is missed.

Are Beta features included in uptime credits?

No. Beta features are included and supported, but they are not covered by uptime credits.

How can I report a security issue?

Email security@eza.co.ke. Do not send secrets, full database exports or customer personal data in the first report.

Read the security details before you deploy

Review the DPA, SLA and public status page. Then deploy your app from Git and pay in KES by M-Pesa.