Hetzner is great but it's not a good choice for companies which really care.
Your data is not encrypted in rest.
Their security is not bad but someone can easily plugin whatever they like.
Try this at Google. Google not just has much stricter physical access control but also FULL control over the hardware. They know the firmware of the Mainboard. The server don't even unencrypt and start if you move them out of their Datacenter.
Google doesn't just has ingress egress they have undersea cable.
There is so much difference between hetzner and google it's not the same thing.
> Hetzner is great but it's not a good choice for companies which really care.
Your data is not encrypted in rest.
It's up to you to set up "encryption in rest": E.g setup LUKS on a Hetzner machine.
> Their security is not bad but someone can easily plugin whatever they like.
That's not how it is. Check e.g. this six-year old security video from Hetzner: Hetzner is great but it's not a good choice for companies which really care.
Your data is not encrypted in rest.
Their security is not bad but someone can easily plugin whatever they like.
I know the video quite well and I also have stuff on hetzner.
But it's just levels different to Google.
I have a small startup at hetzner.
But my main job has everything at the big cloud providers because of audit logs, high slash, global network etc. And no the hetzner video shows already that hetzner can't fullfil all required security certifications.
They have rows and rows of desktop PCs there.
With 'really' care I mean if you process millions or billions you just don't go to hetzner.
And doing encryption on rest with what decryption method? Manual unlock through a remote console?
At Google you literally have encryption on rest by default with key rotation build in and you can use your own keys.
Your data is not encrypted in rest.
Their security is not bad but someone can easily plugin whatever they like.
Try this at Google. Google not just has much stricter physical access control but also FULL control over the hardware. They know the firmware of the Mainboard. The server don't even unencrypt and start if you move them out of their Datacenter.
Google doesn't just has ingress egress they have undersea cable.
There is so much difference between hetzner and google it's not the same thing.