Security & compliance

Security, compliance and where your data lives.

You manage your projects. We manage everything else: Redmine itself, servers, patching, backups, and certifications.

You manage your projects. We manage everything else.

What you control

  • Full Redmine admin access
  • Users and roles
  • Permissions
  • Workflows
  • Custom fields and trackers
  • Project structure
  • Plugin configuration
  • Your data

What we manage

  • OS and security patching
  • Uptime and scaling
  • Encrypted backups with point-in-time recovery
  • TLS in transit
  • Disaster recovery
  • The certifications below

Certifications.

HAZERCLOUD maintains active ISO/IEC 27001 certification, and RedminePRO runs entirely on AWS data centers certified for SOC 1, SOC 2, PCI-DSS, and ISO/IEC 27001.

Data protection

AES-256 encryption at rest via AWS KMS (FIPS 140-2 validated), TLS 1.2+ in transit, encrypted continuous backups with point-in-time recovery.

Region & residency

Choose your region at signup, and your data stays there. SSD-fast infrastructure in the US, EU, and India, with encrypted backups and validated disaster recovery.

US
EU
IN

Access control.

Full admin access is yours from day one, on every plan
SSO via Google from Plus and Microsoft / Entra from Business, with an org-wide enforcement toggle
Audit-relevant activity stays inside your own Redmine workspace
Your files and database, provided on request if you ever want to self-host again

ISO/IEC 27001

HAZERCLOUD maintains active ISO/IEC 27001 certification covering its information security management system, and RedminePRO operates inside that certified ISMS. The distinction matters: the certificate belongs to the operating company and its security processes, and RedminePRO runs within them. Underneath, RedminePRO is hosted entirely on AWS, whose data centers hold SOC 1, SOC 2, PCI-DSS and ISO/IEC 27001 certifications. Payments are handled by Stripe, a PCI Service Provider Level 1, so card data never touches RedminePRO systems. If your organization carries its own SOC 2, HIPAA or similar obligations, we can support you in meeting them: we describe the certifications the infrastructure holds rather than claiming certificates the product does not carry.

GDPR and where your data lives

You choose your region at signup (US, EU or India) and your data stays there. For European teams that means EU data residency without a workaround; for Indian and APAC teams, India is a residency option no other managed Redmine host in this market offers. Encryption is on by default: AES-256 at rest via AWS KMS (FIPS 140-2 validated) on all databases and disk volumes, and TLS 1.2+ in transit on every service and API. Backups are continuous and encrypted, with point-in-time recovery. Staff access customer data only when required for support, restricted by job function and monitored, and passwords are stored salted and hashed, not recoverable by our team. Because RedminePRO is standard open-source Redmine, your full data is available on request if you ever want to leave.

Uptime and SLA

RedminePRO's marketing target is 99.99% uptime, and the Business plan carries a contractual 99.9% uptime SLA. Underneath, the platform runs on AWS with continuous, encrypted backups and point-in-time recovery, so an incident is a recovery, not a data-loss event. We monitor availability and health around the clock and handle patching and version upgrades for you, on our schedule, so keeping the service current is our job, not a maintenance window on your calendar.

Security questions.

Do I get full admin access to my Redmine workspace?
Yes, on every plan, from Startup up. You configure users, roles, workflows, and plugins exactly as you would self-hosted.
What does HAZERCLOUD manage vs. what do I manage?
We manage Redmine itself along with the server, OS, patching, backups, and uptime. You manage your projects: workflows, issues, roles and configuration.
Where is my data hosted?
AWS in the US, EU, or India, your choice at signup.
Can I export my data and leave?
Yes. We'll provide your full files and database on request, so you can self-host any time. No lock-in.