EnglishFrançais

Jahia Cloud: secure and managed hosting for enterprise websites and portals

Jahia Cloud hosts and runs your Jahia websites and portals for you: our team handles the servers, the security, and the day-to-day operations, keeps each site isolated and monitored, and brings the certifications and clear responsibilities your security and procurement teams will ask for.

  • Automatic backups and triple redundancy
  • Enhanced performance, fast response times even during traffic spikes

Get a demo

99,9%

Production availability SLA

ISO 27001

Certified since 2019

100%

Single-tenant isolation

GDPR

Compliant by design

What is Jahia Cloud ?

When you run your websites on your own servers, your teams maintain those servers, keep the operating system and Java up to date, set up the firewalls, run and test the backups, and apply every security patch. Each of these is specialist work. And the more sites you run, the heavier it gets.

Jahia Cloud takes that work off your plate. Our team runs the software and the servers, while you keep control of governance, your domain names, and any custom development. It runs every Jahia product, on the cloud provider and region you choose.

Chrono

Managed operations

Our team installs, updates, patches, and scales the platform, so you no longer have to look after infrastructure.

Note

You stay in control

Create, configure, and manage every environment from one dashboard, with access limited to the people you choose.

Liens

Built to stay up

In production, every component runs in several copies, so your sites keep serving visitors even if one fails. Backed by a 99.9% uptime commitment.

Certified UE or US hosting

ISO 27001, HIPAA, PCI DSS SAQ A, and GDPR by design, with hosting in the EU or the US.

Security

Jahia Cloud security, configured and operated for you

On Jahia Cloud, the security around your site is set up and run by our team.

  • Managed WAF: a web application firewall blocks malicious traffic before it reaches your site. On AWS, protection against large-scale network attacks (AWS Shield Standard) is included at no extra cost.
  • Always-current rules: when a new threat appears, firewall rules update automatically. No ticket to open, no patch to wait for.
  • Encrypted and isolated: your data is encrypted where it's stored, and each environment runs on its own private network, walled off from the others.
  • Private link to your systems: connect Jahia Cloud to your internal applications over IPsec, an encrypted tunnel you configure yourself from the Jahia Cloud console.
Site

Single-tenant isolation in Jahia Cloud

Every Jahia Cloud environment is yours alone, never shared with another customer. This is built into the design, not an option to switch on, and it is what keeps your data separate.

  • Nothing shared: your servers, services and storage are never pooled with another customer's.
  • Three live copies: in production, your database and file storage run as three synchronized copies, so the service keeps running if one fails.
  • Encrypted end to end: at rest and in transit, on AWS and OVH alike, with no configuration on your side.
  • Secrets in a vault: passwords and keys stay in a secure vault, never in code or config files, and backups are encrypted and duplicated.
 Infrastructure Built for Global Performance

Jahia Cloud architecture

A secure platform still has to stay online, so availability is built into the way Jahia Cloud is put together. In production, nothing runs on a single machine:

  • Redundant everywhere: databases, file storage, the servers that deliver your pages and the load balancer each run in more than one copy. If one fails, another takes over.
  • Zero-downtime updates: new versions are switched in with a blue-green deployment, so your visitors never see an interruption.
  • Scales with traffic: during a spike, servers are added automatically, then released once the peak passes.
  • Encrypted connection to your IS: your own systems reach Jahia Cloud through an IPsec tunnel, never over the open internet.

Jahia Cloud availability and SLA

The Jahia Cloud service-level agreement is the uptime our team commits to. It applies to production and is checked every minute. Production is built for high availability with backup copies of each component.

99,9%

Production availability SLA, checked every minute

X3

Redundant database and file-store nodes in production

0

Downtime during upgrades, using blue-green deployment

24/7

Monitoring and alerting through Datadog

Security controls inside the product

Security does not start with hosting. The Jahia software itself, wherever you run it and even on your own servers, comes with protection built in.

Protection against web attacks

Jahia blocks common web attacks, such as forged requests, and only lets approved code and resources load on a page.

Liste

Editor content sanitisation

HTML filtering sanitises what editors publish, so unsafe markup never reaches the live site.

Lock

Authentication and SSO

Multi-factor authentication is built in, and people log in with your existing company accounts through single sign-on (OAuth2 and SAML).

Profil

Role-based access control

Native RBAC and ACLs define exactly who can see and do what.

Vulnerability Management

 Infrastructure Built for Global Performance

How Jahia handles vulnerabilities

Good security is also about process, and Jahia keeps its process open. You do not have to take our word for it, you can check how the software is built and kept safe:

  • SBOM and VEX on demand: download the full list of components inside Jahia, plus a report of known vulnerabilities and whether they actually affect you.
  • Every change reviewed twice: security engineers and AI review each change, which then goes through automated security tests before it ships.
  • Scanned daily, pen-tested regularly: the code is analysed every day, and 3 to 4 component vulnerabilities are examined each week on average.
  • Disclosed, then fixed: when a vulnerability is found, we publish it openly and patch it for Cloud and on-premise customers alike.

Jahia Cloud certifications and compliance

Jahia Cloud's security is checked and certified by independent bodies, so you are not relying only on our word. 

ISO 27001

International standard for managing information security.

HIPAA

US rules for protecting patients' health data.

PCI DSS

Security standard for handling payment card data.
Jahia is not PCI-certified as a payment processor but supports secure integrations with PCI-compliant third-party systems.

GDPR

EU regulation for protecting people's personal data.

AWS Foundational Technical Review

AWS review confirming security, reliability, and operational best practices.

You choose where your servers and data are hosted: France (OVH), Ireland or North Virginia (AWS), or Singapore. Keep your data in the EU for sovereignty and GDPR, or host it close to your users elsewhere.

Shared responsability model

Control depends on a clear boundary. On Jahia Cloud, who handles what is defined from the start, so there is no grey area.

Jahia operates

 

  • The software and the infrastructure
     
  • Continuous access to backups, restore, and restart
     
  • Logs and monitoring
     
  • Hotfix deployment and disaster recovery

You own

 

  • DNS configuration and validation
     
  • Custom development on the platform
     
  • Your own modules and extensions

A platform you control without the operational load

With Jahia Cloud, the work of hosting, securing, and keeping your sites available moves to the Jahia Cloud team, while governance, your domain names, and your custom development stay with you. Your teams stop maintaining servers and get back to building sites, on a platform that is isolated, encrypted, certified, and watched around the clock.

Get a quote for your project

Our experts help you define the right platform, hosting, and infrastructure tier for your needs

image-internationalized