Security and trust

Where your data lives and how it is protected

When you commission a website, you want to know three things: where your data lives, how it is protected, and whether you can always get it back. This page answers all three.

EU-hosted admin
A separate database per customer
Your content belongs to you
At a glance
What you can rely on
EU-hosted admin
on Vercel in an EU region
Separated data
a separate database per customer
Automatic backups
earlier versions can be restored
GDPR-compliant
DPA available on request
Topics at a glance

Security from the infrastructure to your data export

If you need more detail or evidence on any point, just ask us.

Hosting and infrastructure

The JetPages admin runs on Vercel in an EU region. Your website is served as a finished, cached copy through a global edge and CDN network, close to your visitors — on Vercel (EU region) or Cloudflare, depending on the project.

  • Admin on Vercel in an EU region
  • Delivery through a global edge and CDN network
  • Images served through ImageKit as a CDN

A separate database per customer

Your content lives in its own database that no other customer uses — cleanly separated instead of a shared data pool.

  • Fully separated data storage
  • No shared database with other customers

Backups and version history

Content is backed up automatically, and earlier states can be restored. Independently of that, JetPages stores every version of every page — per language, with date and user.

  • Automatic backups of your content
  • Earlier states can be restored
  • Version history for every page and language

Access protection

Only your team gets into the admin — with two-factor authentication or single sign-on if you want. The delivered website is additionally hardened with strict security headers and HTML sanitization.

  • Two-factor authentication
  • Single sign-on via OpenID Connect as an enterprise option
  • Signed preview links for drafts
  • Strict security headers and HTML sanitization

GDPR and DPA

We work in a GDPR-compliant way. We provide a data processing agreement (DPA) on request.

  • GDPR-compliant collaboration
  • Data processing agreement (DPA) on request

No WordPress, no plugins

JetPages is its own codebase with no WordPress and no third-party plugins. Outdated plugins are a common entry point for attacks — that attack surface simply does not exist with JetPages.

  • No plugin security holes
  • No update obligation on your side
Content ownership

Your content belongs to you

You stay independent: when the contract ends, you receive your content free of charge in a common format, for example JSON or CSV — as set out in the terms.

A basic export of your content is free of charge
A common format such as JSON or CSV
Set out this way in the terms
Frequently asked questions

Questions about security and data protection

The JetPages admin runs on Vercel in an EU region. Your website runs on Vercel (EU region) or Cloudflare, depending on the project, and is served as a cached copy through a global edge and CDN network. Images are delivered through ImageKit as a CDN.

No. Every customer has their own database. Your content does not sit in a shared database with other customers.

JetPages stores every version of a page automatically — per language, with date and user. You can view earlier versions and bring content back from them. Independently of that, content is backed up automatically, so earlier states can be restored as well.

No. JetPages uses no WordPress and no plugins — there is nothing on your side to keep updated. JetCoders takes care of hosting and support.

Your content belongs to you. When the contract ends, you receive a basic export free of charge in a common format such as JSON or CSV. This is set out in the terms.

Yes. We work in a GDPR-compliant way and provide a data processing agreement (DPA) on request.

Next step

Questions about security and data protection?

We answer your questions about hosting, backups, GDPR, and data export, and provide the DPA on request.