{
  "slug": "upcloud",
  "category": "server-hosting",
  "name": "UpCloud",
  "description": "Finnish cloud provider offering virtual servers, GPU servers, managed Kubernetes, databases and object storage in datacenters in Europe, North America, Asia and Australia.",
  "website": "https://upcloud.com",
  "license": null,
  "platforms": [],
  "jurisdiction": {
    "code": "FI",
    "name": "Finland",
    "eyes": null,
    "eu": true,
    "gdpr": true,
    "cloud_act": null
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "D",
  "score": 53,
  "coverage": 100,
  "summary": "UpCloud scores 53 out of 100 (grade D) on the server hosting criteria. It meets 6 of 12 criteria: no ads or data sales, tells users about requests, TLS configuration, security headers, Reverse DNS and IPv6. It partly meets independent audit, transparency report and mail-friendly (port 25). It does not meet open source, no trackers or telemetry and anonymous payment. It is based in Finland: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
  "url": "https://privacyratings.com/server-hosting/upcloud/",
  "markdown": "https://privacyratings.com/server-hosting/upcloud/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "no",
      "evidence": null,
      "note": "Closed source."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "no",
      "evidence": null,
      "note": "The home page loads Google Tag Manager."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://upcloud.com/privacy-notice/",
      "note": "Funded by paid hosting, and the privacy notice says personal data is not sold."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://upcloud.com/media/upcloud_iso27001_2026.pdf",
      "note": "Only the ISO 27001 certificate is public, not the audit report."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://upcloud.com/privacy-notice/",
      "note": "The privacy notice says data is disclosed only in response to lawful requests or legal process. No request counts are published."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://upcloud.com/privacy-notice/",
      "note": "The privacy notice says customers are informed in advance of disclosures to authorities where possible."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=hub.upcloud.com&hideResults=on",
      "note": "Grade A+"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=hub.upcloud.com",
      "note": "Grade A+ (105/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "port_25": {
      "title": "Mail-friendly (port 25)",
      "weight": 1,
      "answer": "partial",
      "evidence": "https://upcloud.com/docs/getting-started/free-trial/",
      "note": "Port 25 is blocked by default on all accounts, and non-trial customers can ask support to unblock it."
    },
    "reverse_dns": {
      "title": "Reverse DNS",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://upcloud.com/docs/products/networking/dns/",
      "note": "Reverse DNS for every IP address can be changed in the control panel or through the API at no cost."
    },
    "ipv6": {
      "title": "IPv6",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://upcloud.com/docs/products/networking/public-network/",
      "note": "Every cloud server gets one IPv4 and one IPv6 address by default."
    },
    "anonymous_payment": {
      "title": "Anonymous payment",
      "weight": 1,
      "answer": "no",
      "evidence": "https://upcloud.com/docs/getting-started/billing/payment-methods/",
      "note": "Payment is by card, PayPal, Apple Pay or Google Pay. Cryptocurrency is not accepted."
    }
  },
  "tests": {
    "ssllabs": "A+",
    "observatory": "A+",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [
      {
        "name": "Google Tag Manager",
        "host": "www.googletagmanager.com",
        "effect": "no"
      }
    ],
    "tested_at": "2026-10-01T10:59:37.029Z"
  },
  "last_modified": "2026-10-01T11:14:42Z"
}