What happens to your site if something happens to us
A straight answer to the question people ask before moving off a VPS: where the files live, what goes down with the panel, who makes backups and when, and what happens if you do not pay.
Serving does not depend on the panel
Sites are served by a separate service straight from S3 storage. If the panel, builds or the database are down, published sites keep opening: serving does not depend on them at request time.
Daily backups at two providers
The database and configuration are exported every day, encrypted before upload and kept for 14 and 60 days. Site files are mirrored to another cloud provider's storage with a key that is not allowed to delete: even losing the main storage does not lose the sites.
Builds in a sandbox
Projects with a build step are built in an isolated, unprivileged container: no kernel capabilities, memory and process limits, a timeout. Archives are checked for zip bombs and for paths escaping the folder before unpacking.
Service files are never published
.git, .env, .ssh, .npmrc and other service folders and files are dropped on every upload — from the panel, the CLI, an archive or Git — with a notice. Leaked keys and tokens in the remaining files are caught by publish checks.
HTTPS without waiting
Certificates for subdomains and custom domains are issued and renewed automatically, and warmed up after the first deploy so the first visitor never lands in the issuance window.
Nothing is deleted silently
A deleted site stays in the trash for 24 hours. An overdue subscription does not wipe your sites: they keep working for a day, then projects are paused, and only after 15 days do sites go to the trash for another week, with an email at every step.
Data and law
The Terms of Service, Privacy Policy, data processing agreement with the list of subprocessors and terms for site visitors are translated for convenience; the Russian originals are legally binding.
What we do not promise
Certifications
We do not hold ISO 27001 or SOC 2. What we have are the measures described here and documents you can read.
Server-side code
Tuqo serves static files only: no SSR, functions or databases. That rules out a whole class of vulnerabilities, but it also means we will not host your backend.
Storage abroad
Data and backups stay in Russia. If your project needs EU jurisdiction, we are not the right host.
Reliability — frequently asked
What happens to my site if the panel goes down? +
It keeps opening. Serving is a separate service that reads files from storage; the panel, builds and the database are needed to make changes, not to answer visitors. That is exactly why we keep them apart.
How often are backups made, and who can access them? +
Every day. Database and configuration dumps are encrypted before they are sent to backup storage and are kept for 14 and 60 days. Site files are mirrored to a second provider with a key that cannot delete. Only the platform owner has access to the backups.
Do you have ISO 27001 or SOC 2 certification? +
No, and we do not claim otherwise. We describe what is actually in place: service isolation, encrypted backups, a build sandbox, least privilege. If your environment requires formal certification, it is fairer to say so up front.
What do you do about DDoS? +
Serving sits behind a protected entry point with rate limiting and filtering of known-bad traffic; the limits have headroom. We do not publish the details: they are part of the protection. If a site goes over its plan's traffic, it is not switched off: we warn you at 80% and 100%.
What happens if I do not renew my plan? +
Nothing irreversible right away. For a day, sites work as before. Then projects are paused, and after 15 days the account moves to the Free plan: sites go to the trash for a week, domains are switched off but not deleted. Every step comes with an email. Once you pay, everything comes back.
Where is the data stored? +
Servers in Russia, site files in Russian S3 storage, backups at a Russian cloud provider. The list of subprocessors is published in the DPA.
How do I report a vulnerability? +
Email support@tuqo.dev with the subject “security”. We reply with substance, not a form letter, and we do not go after good-faith researchers.
Your site keeps running, whatever happens
Backups, the build sandbox and serving that does not depend on the panel are on for every site, on every plan.