Choose private infrastructure
Host data and apps on infrastructure that reduces default surveillance and vendor lock-in.
Target outcome
Critical services run on infrastructure with documented metadata exposure
Do this first · quick win
If you only do one thing today: map one critical service (chat, files, or site) and list who can see metadata at rest and in transit.
Setup queue
Start with verified tools
Compare the fit, keep the ones you want in My Stack, then open the verified setup guidance.
Choose Nym when network-level metadata protection matters as much as application encryption.
More compatible tools (2)
Choose Aleph when you want decentralized compute/storage instead of a single cloud vendor account.
Choose Fileverse when document publishing and collaboration are part of your stack.
Understand · act · verify
Your path
Nothing is detected automatically. You decide when a step is done or needs another review.
- 1
Inventory the services you run — storage, compute, DNS, email — and note who operates each layer.
Step 1 · Not started
- Service inventory complete: You have a list of every layer (DNS, compute, storage) and who can see metadata at each.
- 2
Pick one pilot workload (file share, API, or static site) to migrate to privacy-oriented hosting.
Step 2 · Not started
- Pilot workload selected: One low-risk workload is chosen with clear success criteria before production migration.
- 3
Enable encryption in transit everywhere and document key custody before moving production data.
Step 3 · Not started
- 4
Deploy the pilot on Nym, Aleph, or a self-hosted stack and run load and recovery tests.
Step 4 · Not started
- 5
Publish a short runbook covering backups, key rotation, and what metadata the operator can still see.
Step 5 · Not started
- Operator runbook published: Backups, key rotation, and residual metadata exposure are documented for the team.
How you know it worked
- Critical services run on infrastructure with documented metadata exposure
- Encryption in transit and key custody are defined before production data moves
- Your team has a tested backup and recovery runbook
Watch out
Decentralized infra still exposes payment, DNS, or support metadata if configured carelessly.
Running production without tested backups is not privacy — it is fragility.
A domain registered to your legal name links infrastructure to your identity in WHOIS and billing records.
Key terms
- Metadata at rest
- Information about stored data — filenames, access logs, sizes — visible to the storage operator even when files are encrypted.
- Key custody
- Who holds encryption keys; if the host holds them, they can read your data regardless of marketing claims.