Security, compliance, and operational transparency for teams evaluating Thalassa Cloud. Hosted in the Netherlands, operated to ISO/IEC 27001 requirements, and built on a clear shared responsibility model.
Signed supply chain, least privilege, encryption at rest and in transit, and STRIDE-based threat modelling across every service.
Read platform securityWe secure the platform; you secure what you deploy. A clear ownership map for risk assessments, audits, and architecture reviews.
View responsibility modelPlatform incidents and regional maintenance are published on our status page. Service-specific maintenance is communicated by email.
How we communicateReport spam, phishing, malware, or network abuse originating from Thalassa Cloud infrastructure. We investigate and act promptly.
Report abuseAll infrastructure is hosted in the Netherlands within the European Union. Data is encrypted at rest and in transit. Platform operations are logged for compliance investigation.
Thalassa Cloud operates its information security management system (ISMS) in accordance with ISO/IEC 27001. We are expected to complete certification by the end of Q3 2026.
Security on Thalassa Cloud follows the industry-standard shared responsibility model. Thalassa Cloud secures the underlying platform — data centers, control plane, storage fabric, and managed service runtimes. You secure what you deploy, configure, and operate on top of it.
| Area | Thalassa Cloud | You |
|---|---|---|
| Physical & platform infrastructure | Data centers, hypervisor, control plane, storage backend | — |
| Identity and access | Authentication infrastructure, IAM service, OIDC endpoints | User management, RBAC, service account policies |
| Network security | Network isolation, DDoS mitigation, platform segmentation | VPC design, security groups, firewall rules |
| Data protection | Encryption at rest and in transit; platform service backups | Data classification, KMS keys, workload backups |
| Incident response | Platform-level incidents on shared infrastructure | Workload incidents, misconfigurations, compromised credentials |
These principles apply across the control plane, data plane, build systems, and operational tooling that make up the Thalassa Cloud platform.
status.thalassa.cloud is the authoritative source for platform health. It publishes active incidents, scheduled maintenance, resolved incident summaries, and historical records.
| Scope | Channel |
|---|---|
| Platform or region-wide events | Status page |
| Your Kubernetes cluster | Email + console (within maintenance window) |
| Your DBaaS instance | Email (within maintenance window) |
| Your compute instance | Email (within maintenance window) |
If you believe abusive activity is originating from an IP address, domain, or service hosted on Thalassa Cloud, submit a report to Thalassa Cloud support with as much detail as possible.
Include date and time, source indicators (IPs, domains, URLs), activity type, evidence, impact, and your contact details.