"We can't read your data" is an easy thing to say. This page is the hard version: exactly what Cephlon can access on a Metal server, what we log, and how to shrink both — down to a power switch.
We collect only what we need to operate the service — billing records and network flow data for abuse prevention. No content inspection, no analytics mining, nothing sold. Ever.
That line is on every Cephlon page. This page is the proof behind it: what we can technically access on a Cephlon Metal server, what we deliberately log, and the modes that shrink our access further — all stated with the trade-offs included, because a transparency page without trade-offs is just marketing.
A Cephlon Metal server is a dedicated physical machine. You install the operating system (or we preinstall your choice at handover); the accounts, the keys, and everything on disk are yours. On Metal tiers there is no shared hypervisor between us and your workload, and no Cephlon agent running inside your OS.
What we operate is everything around the machine: power, network, and the out-of-band management controller (iDRAC) used for hardware support. The rest of this page is about exactly what that access does and doesn’t allow — and how to reduce it.
Shared Instances run on a Cephlon-operated hypervisor, isolated per customer, with the same logging rules described below.
Nothing is ever sold or shared for marketing.
Every server ships in one of three modes. You choose at provisioning, and you can tighten later. Modes 2 and 3 combine.
We keep iDRAC (out-of-band console) access for fast hardware support: remote power control, reinstalls at your request, and the server’s console display. Stated honestly, that console shows whatever your machine prints to its screen. We have no login to your OS and no access to your files — your accounts and keys are yours, and we don’t log in.
You set the iDRAC password yourself, and our console access is surrendered. What we keep is power-cycling through the rack PDU — and that’s it. The trade-off, stated plainly: hardware diagnosis becomes slower and needs your cooperation, because we can no longer see what the machine reports.
At install, we walk you through LUKS full-disk encryption with keys only you hold. From that point, even physical access to the drives yields ciphertext. The trade-off is real: lose the key and nobody — including us — can recover the data. That is the point.
A Data Processing Agreement (DPA) is available for business customers (PIPEDA processor posture) — ask us at contact@cephlon.com.
We publish our real, measured uptime and back our SLA with defined service credits — the commitment and the credit schedule live on the SLA. Failover is stated honestly too: re-routing happens within minutes. That’s the bound we measure, so that’s the bound we publish. And when something breaks, it goes on the status page.
Questions this page doesn’t answer? contact@cephlon.com — a human who owns the hardware answers.