Security you can actually verify
Real hardware isolation, a management plane your VM can't touch, backups on a separate pool, and 2FA on your account — described plainly, with no invented badges. Here's exactly how we protect your servers and your data.
A real machine boundary between tenants
The strongest isolation on the platform is the default one: every customer gets a full virtual machine, not a slice of a shared container.
Full KVM virtual machines
Every customer runs inside a full KVM virtual machine with hardware-assisted virtualization — not a shared container carved out of someone else's kernel. You get a real, isolated machine boundary.
No noisy-neighbour containers
Because each server is its own VM, another tenant's workload can't read your memory or reach into your filesystem. Strong tenant isolation is the default, not an upgrade.
Patched Proxmox hypervisor
Your VMs run on a maintained, regularly patched Proxmox hypervisor on enterprise hardware — the foundation we keep current so the isolation boundary stays sound.
The blast radius stops at your VM
Our network is built so a compromised or attacked server can't become everyone else's problem — starting with a firewall that refuses to let VMs talk to the host.
Management plane walled off
The host firewall drops all traffic from customer VMs to the host. Even a fully compromised server can't reach our hypervisor, management plane, or database — the blast radius stops at your VM.
Edge DDoS mitigation
Volumetric attacks are absorbed and filtered at the network edge before they reach your server, so an attack aimed at one tenant doesn't take the platform — or you — offline.
Managed firewall & dedicated IPv4
A managed firewall guards every server, and an optional dedicated IPv4 gives you a clean, static address with no shared NAT and no noisy neighbours on your IP.
Encrypted in transit
HTTPS everywhere with Let's Encrypt certificates, HSTS to force secure connections, and secure cookies on the dashboard — so your session and control-panel traffic stay private in transit.
Backups that survive a bad day
Redundant, self-healing storage for your live data, plus automatic snapshots kept somewhere separate — so a single failure or fat-fingered command isn't the end of the story.
Snapshots to a separate pool
Automatic snapshots stream to a separate ZFS backup pool, kept off your server's own disks — so your data can survive a mistake, a bad deploy, or a full host failure.
One-click restore
Roll back to a known-good point in time straight from the dashboard. No support ticket, no waiting — recovery is something you can do yourself, when you need it.
NVMe on a ZFS mirror
Your live data sits on enterprise NVMe in a redundant ZFS mirror. ZFS checksums every block and self-heals from the mirror, so silent corruption doesn't quietly rot your data.
Lock down the front door
Strong infrastructure only matters if your account is hard to break into. These are the controls guarding access to everything you run on Nxeon.
Two-factor authentication
Protect your account with TOTP-based 2FA from any authenticator app, so a leaked or reused password alone can never be enough to reach your servers.
Scoped API tokens
Automate with API tokens that carry only the access they need. Issue them per integration and revoke any one instantly without touching your password.
Session controls
See and manage the sessions signed in to your account, so you can sign out a device you no longer trust and stay in control of who has access.
Rate-limited authentication
Login and sensitive endpoints are rate-limited to blunt brute-force and credential-stuffing attempts before they get anywhere near your account.
Your data belongs to you
Trust cuts both ways: you should be able to leave as easily as you arrived. We build for portability, not for lock-in.
Your data is yours
You get full root on your own server. What you run and what you store belongs to you — we don't rummage through your VMs and we don't sell your data.
Export and leave anytime
No lock-in and no hostage-taking. Snapshot your server, pull your data, and move on whenever you like — the exit is as open as the front door.
Privacy by default
We collect what we need to run your account and bill you accurately — nothing more. Your workloads stay yours, and we don't monetise your data on the side.
The same honesty, applied to money
Security is trust, and so is billing. We price plainly, show real renewal costs, and make leaving a single click — because a customer who can walk away is one we have to keep earning.
Clear, upfront pricing
The price on the page is the price you pay. No mandatory add-ons hidden at checkout and no surprise line items on your first invoice.
Honest renewal prices
When something is discounted for a first term, we show the real renewal price right next to it — so you're never ambushed by the second bill.
Cancel in a click
Turn off auto-renew whenever you want, straight from the dashboard. Billing simply stops at the end of the period — no retention maze, no phone call.
What we don't claim
We won't put a badge on this page we haven't earned. Nxeon does not currently hold formal SOC 2, ISO 27001, or PCI certifications, and we'd rather tell you that than pretend otherwise. Everything above describes controls that are live today. If a compliance program matters for your workload, talk to us about where we're headed.
Deploy your first server in under a minute
No credit card required to get started. Spin up a VPS, break things, and only pay for what you keep running.