What we back up
- Postgres — your workflows and execution history
- The credentials store
- The
N8N_ENCRYPTION_KEY, stored separately - Configuration and environment
- Custom nodes and binary data
Security and backups are the reason to pay for managed hosting. In late 2025 and early 2026 n8n disclosed multiple critical, unauthenticated remote-code-execution vulnerabilities — several at the highest severity possible, at least one added to the US government's known-exploited list — with tens of thousands of unpatched instances sitting exposed online. Most self-hosters never patch. We give you an isolated, backed-up instance and the infrastructure to patch safely on your own schedule — your n8n version and security patches stay in your control.
You control when your n8n version is updated. We recommend watching n8n's own release notes and security advisories and updating promptly. What we provide makes that safe to do.
Your instance is single-tenant, with its own database and encryption key, so an update on your instance never touches anyone else's.
Daily off-site backups, tested monthly, mean an update that goes wrong is recoverable.
Edge protection and secure defaults reduce your exposure while you decide your own update schedule.
Server and OS maintenance windows are announced; on Scale they are coordinated with you. Your n8n version and its updates remain yours to schedule.
One instance per customer. A separate Postgres database, separate credentials and a separate N8N_ENCRYPTION_KEY stored apart from the database it decrypts. Container CPU and memory caps, network egress limits and per-instance webhook URLs.
Nothing is shared between customers — not the process, not the database, not the key.
Daily, encrypted, off site — and restored on a schedule so we know they work.
N8N_ENCRYPTION_KEY, stored separatelyThe honest answer to "what if you disappear?"
Request a full export at any time, or on cancellation: your database plus your workflow JSON. Take it to another host and run it. There is no lock-in beyond the ordinary work of switching providers.
| Outcome | We secure | You secure |
|---|---|---|
| Server, OS, Docker and network | Yes | — |
| n8n version and security patches | — | You |
| Troubleshooting inside your workflows | — | You |
| Backups, encryption at rest and restores | Yes | — |
| Edge protection and secure defaults | Yes | — |
| Your workflow logic and what it does | — | You |
| Your third-party API keys and credentials | — | You |
| Your login hygiene and who you share access with | — | You |
Uptime figures below are targets, not guarantees. The Business column is shaded as the most common production choice.
| Outcome | Starter | Business | Agency | Scale |
|---|---|---|---|---|
| Uptime target | 99.5% | 99.7% | 99.9% | 99.9% |
| Support response target | 24–48h | Next business day | 4–8h | 4h |
| Incident / emergency response | Best effort | Emergency line | Priority + emergency line | Priority, 4h |
| Backup retention | 7 days | 30 days | 30 days | 30–90 days |
| Restore target (RTO) | < 4h | < 4h | < 2–4h | < 2h |
| Maintenance windows | Announced, off-peak | Announced, off-peak | Announced, off-peak | Announced + coordinated |
Exclusions: scheduled and announced maintenance, customer misconfiguration, third-party API or DNS/registrar outages, force majeure, and instances suspended for abuse. Full terms are in the Terms.
You choose whether your instance runs in the US or the EU. We operate on a GDPR basis and a Data Processing Agreement is available — see the DPA and the Privacy Policy, including the sub-processor list.
We hold no formal certification such as SOC 2 or ISO 27001 yet, and we don't claim one.
You do. We recommend watching n8n's own release notes and security advisories and applying updates on your own schedule. We provide the isolated, backed-up infrastructure - including Cloudflare edge protection - that makes doing this safely straightforward.
Yes. Backups run daily. Retention is 7 days on Starter and 30 days on Business and above, stored off-site and encrypted at rest.
Yes, every month. An untested backup is not a backup.
Yes. Every customer gets a separate instance, database and encryption key, each with its own CPU and memory limits. Nothing is shared between customers.
Dedicated, isolated, monitored, and backed up with tested restores — with a human on support for your infrastructure. Standard migration is free.