How to Securely Host Your Dedicated/VM/Cloud Services including Cryptocurrency
The most honest thing for me to say, is that if your company is equipped and has strong physical security 24/7, redundant power and redundant internet, you may not even need the services of my company, at least for the physical hosting portion. This assumes you have 24/7 staff to maintain the network and that you have your own racks, servers, inventory etc… I would argue even if you don’t that this may make more sense to acquire and my company does help consult by both selling and physically managing your on-premises deployment. But, if you already have the manpower and hardware, you won’t need my company or any company and that is often the best way to go. There is still the case for off-site diversity, but if you were going to choose a single Cloud provider/Zone, I will argue it is probably fine to self-host your company as many companies have done for a long time. This also assumes you are in a safe jurisdiction and you have a secondary place to keep that data for redundancy or geo-balanced Kubernetes/Docker Swarm etc..
The reality with a lot of companies is that the ideal situation above does not check all of the boxes, it’s ideal because it’s often not entirely possible. Thus, most companies often need at least some outside help or hosting. In that case, you’ll need a trustworthy company, in a trustworthy jurisdiction who has both the technical and legal know how to provide your services securely and privately. This is something I argue that 99% of companies can’t, won’t and don’t do and is why so many companies and wealthy individuals choose services from people like me.
How can you secure your servers regardless of where they are hosted?
This makes the assumption you haven’t purposely chosen an intelligence or government affiliated or US big tech company, or one under the direction of entities that I’ve described, which I argue is the majority of the tech industry. I’m assuming you’ve chosen a private and independent company like mine.
I also assume you have a clustered server setup that is like what my company provides, where the drives are completely encrypted. Once you’ve achieved this and you have full control over the servers, you will have the highest levels of privacy. The host, not even us, should be able to access or monitor your data, assuming your data is properly encrypted in transit.
At this point assuming your servers are properly secured, the next thing that could threaten you is if somehow someone got your physical SAS/NVME drives and extracted the data but this should not be possible as long as you follow the right procedures to encrypt your data AND you delete the original provider key slot.
Even if your drives and servers were stolen like the EU or US does frequently, they would not have access to your data at this point. As the provider, we would be unable to comply with any legal order to provide your data since we don’t have access either, only you, the customer has the key.
And if you’ve chosen a company like mine, which is in a secure jurisdiction and ignores frivolous foreign requests, then you’re covered unlike if you were to host in the EU or US, or if you chose an EU or US company that had servers overseas.
The big mistake many make
Some of my friends and clients have done everything wrong with this advice. I’ve seen companies take what I’ve advised, like above and then they say “OK we’ll choose a EU or US Cloud or Server Provider with servers in Hong Kong”. This completely defeats any attempt at privacy or stopping frivolous requests, since the US or EU government will just compel your hosting company to tap you and hand over your data. It doesn’t matter that the servers are hosted overseas when the company itself is either registered in the US or EU or a subsidiary of the EU or US company.
The other thing many people misunderstand is the term “fully encrypted”. If you aren’t given a key to decrypt the contents of the data and if you can’t control or revoke key access to the data, it means you aren’t secure and your provider is in full control over the encryption. It would be like saying “my house is secured by 10 keys” but then you’ve given copies of the key to the whole neighbourhood.
Higher levels of protection
To HNW individuals and HNW companies, sometimes they want to take it a step further and have their data stored in a “secret bunker”. This means we establish an exclusive hosting facility that is completely physical separated from all other clients just for their exclusive use. The facility and IP space will have no trace to either our company or you as the customer, so it’s not possible to do a scan and for anyone to even find your infrastructure.
Jurisdictions that best refuse US or EU requests
Hong Kong offers the overall easiest system to access and use and is very resistant to foreign requests and even snubbed a US request to seize a $500M USD Russian Yacht. But if you want one notch higher, then I argue raw data storage in the People’s Republic of China is the ultimate solution. You can of course still use the method I describe in less safe jurisdiction. For example we would especially recommend our international clients that host their data in Canada, still have a fully encrypted server service.
Even if you wanted to host in Canada, the US or EU, at least your personal information would be shielded by a company in China. This means the US cannot subpoena the China company to give out their client information like they would to a domestic US company or use back channels that they have with US big tech.
Mainland China is number one in my opinion for this purpose, because it is actually illegal for a Chinese company to comply with a foreign request by sending data or information overseas without the permission of the Chinese government.
For example Article 36 of the “Data Security Law of the People’s Republic of China” stipulates that any foreign requests by other government or foreign law enforcement, must be approved by the Chinese government. This is not going to be the case where the US threatens a small EU country or another small country is able to illegal obtain your data through coercion and threats.



