EnglishFrançais

Jahia Cloud: secure and managed hosting for enterprise websites and portals

Jahia Cloud hosts and runs your Jahia websites and portals for you: our team handles the servers, the security, and the day-to-day operations, keeps each site isolated and monitored, and brings the certifications and clear responsibilities your security and procurement teams will ask for.

  • Automatic backups and triple redundancy
  • Enhanced performance, fast response times even during traffic spikes

Get a demo

99,9%

Production availability SLA

ISO 27001

Certified since 2019

100%

Single-tenant isolation

GDPR

Compliant by design

What is Jahia Cloud ?

When you run your websites on your own servers, your teams maintain those servers, keep the operating system and Java up to date, set up the firewalls, run and test the backups, and apply every security patch. Each of these is specialist work. And the more sites you run, the heavier it gets.

Jahia Cloud takes that work off your plate. Our team runs the software and the servers, while you keep control of governance, your domain names, and any custom development. It runs every Jahia product, on the cloud provider and region you choose.

Chrono

Managed operations

Our team installs, updates, patches, and scales the platform, so you no longer have to look after infrastructure.

Note

You stay in control

Create, configure, and manage every environment from one dashboard, with access limited to the people you choose.

Liens

Built to stay up

In production, every component runs in several copies, so your sites keep serving visitors even if one fails. Backed by a 99.9% uptime commitment.

Certified UE or US hosting

ISO 27001, HIPAA, PCI DSS SAQ A, and GDPR by design, with hosting in the EU or the US.

Security

Jahia Cloud security, configured and operated for you

With Jahia Cloud, the security around your site comes set up and managed by our team. It covers four things:

  • A managed Web Application Firewall (WAF) sits in front of your site and blocks malicious traffic before it reaches it, including the request floods used in denial-of-service attacks. Protection against large-scale attacks (AWS Shield Standard) is also included.
  • When a new threat appears, the firewall rules are updated automatically, so your site is protected without waiting for anyone to act.
  • Your data is encrypted while it is stored, and each environment runs on its own private network, cut off from the others.
  • You can link Jahia Cloud to your internal systems through IPsec, an encrypted private tunnel you set up from the Jahia Cloud console.
Site

Single-tenant isolation in Jahia Cloud

Each Jahia Cloud environment is single-tenant, which means it is yours alone and never shared with another customer. This is built into the design, not an option to switch on, and it is what keeps your data separate.

  • Your servers, services, and storage are never mixed with another customer's.
  • In production, your storage and database run as three synchronized copies, so the service keeps running if one fails.
  • Data is encrypted both where it is stored and while it travels, on AWS and on OVH.
  • Passwords and keys are kept in a secure vault, never written into the code or config files, and backups are encrypted and duplicated.
 Infrastructure Built for Global Performance

Jahia Cloud architecture

A secure platform still has to stay online, so availability is built into the way Jahia Cloud is put together. In production, nothing runs on a single machine:

  • Every part runs in more than one copy: the databases, the file storage, the servers that deliver your pages, and the load balancer. If one fails, another takes over.
  • Updates are switched in with no downtime (a blue-green deployment), so your visitors never see an interruption.
  • When a site gets busy, more servers are added automatically, and released again once the peak passes.
  • Your own systems connect to Jahia Cloud through an encrypted IPsec tunnel.

Jahia Cloud availability and SLA

The Jahia Cloud service-level agreement is the uptime our team commits to. It applies to production and is checked every minute. Production is built for high availability with backup copies of each component.

99,9%

Production availability SLA, checked every minute

X3

Redundant database and file-store nodes in production

0

Downtime during upgrades, using blue-green deployment

24/7

Monitoring and alerting through Datadog

Security controls inside the product

Security does not start with hosting. The Jahia software itself, wherever you run it and even on your own servers, comes with protection built in.

Protection against web attacks

Jahia blocks common web attacks, such as forged requests, and only lets approved code and resources load on a page.

Liste

Editor content sanitisation

HTML filtering sanitises what editors publish, so unsafe markup never reaches the live site.

Lock

Authentication and SSO

Multi-factor authentication is built in, and people log in with your existing company accounts through single sign-on (OAuth2 and SAML).

Profil

Role-based access control

Native RBAC and ACLs define exactly who can see and do what.

Vulnerability Management

 Infrastructure Built for Global Performance

How Jahia handles vulnerabilities

Good security is also about process, and Jahia keeps its process open. You do not have to take our word for it, you can check how the software is built and kept safe:

  • At any time, you can download a full list of every component inside Jahia (SBOM) and a report of known vulnerabilities and whether they affect you (VEX).
  • Every change is reviewed by both security engineers and AI, then run through automated security tests.
  • The code is scanned every day and tested by independent security experts on a regular basis.
  • When a vulnerability is found, the Jahia team discloses it openly and fixes it for both Cloud and on-premise customers.

Jahia Cloud certifications and compliance

Jahia Cloud's security is checked and certified by independent bodies, so you are not relying only on our word. 

ISO 27001

International standard for managing information security.

HIPAA

US rules for protecting patients' health data.

PCI DSS

Security standard for handling payment card data.
Jahia is not PCI-certified as a payment processor but supports secure integrations with PCI-compliant third-party systems.

GDPR

EU regulation for protecting people's personal data.

AWS Foundational Technical Review

AWS review confirming security, reliability, and operational best practices.

You choose where your servers and data are hosted: France (OVH), Ireland or North Virginia (AWS), or Singapore. Keep your data in the EU for sovereignty and GDPR, or host it close to your users elsewhere.

Shared responsability model

Control depends on a clear boundary. On Jahia Cloud, who handles what is defined from the start, so there is no grey area.

Jahia operates

 

  • The software and the infrastructure
     
  • Continuous access to backups, restore, and restart
     
  • Logs and monitoring
     
  • Hotfix deployment and disaster recovery

You own

 

  • DNS configuration and validation
     
  • Custom development on the platform
     
  • Your own modules and extensions

A platform you control without the operational load

With Jahia Cloud, the work of hosting, securing, and keeping your sites available moves to the Jahia Cloud team, while governance, your domain names, and your custom development stay with you. Your teams stop maintaining servers and get back to building sites, on a platform that is isolated, encrypted, certified, and watched around the clock.

Get a quote for your project

Our experts help you define the right platform, hosting, and infrastructure tier for your needs

image-internationalized