4 ms·
Trust is one thing but it is also a matter of legal and fiduciary responsibility. They simply *are not able* to do it for legal reasons. When a cloud provider
by janoc 3y ago
Trust is one thing but it is also a matter of legal and fiduciary responsibility.
They simply *are not able* to do it for legal reasons. When a cloud provider contract is signed it is chock full of liability and CYA language to make sure that if the provider makes a boo-boo and the data gets exposed/lost/damaged/etc. they will get hauled in court and driven bankrupt.
The reason for this are often laws - e.g. something like payroll or personal information (e.g. HR) is heavily heavily regulated by law and exposure or loss of such data would get the company in hot water with the regulator. So any service provider must guarantee that this won't happen.
The other reason are contractual relationship with their customers - customer information is heavily NDAed, you can't just share it with whoever you want or even upload it into any sort of cloud. E.g. we have at work restrictions even on things like which geographical location the data can be uploaded to and which not, even on the same cloud provider! The customers don't want to take any chances that e.g. some government will want to "take a peek" - and then e.g. share the information with their competitor. This did happen before.
Good luck to a startup with no name and that can be gone tomorrow with this. Simply isn't going to happen.
- generic92034 3y ago> The other reason are contractual relationship with their customers - customer information is heavily NDAed, you can't just share it with whoever you want or even upload it into any sort of cloud. E.g. we have at work restrictions even on things like which geographical location the data can be uploaded to and which not, even on the same cloud provider! The customers don't want to take any chances that e.g. some government will want to "take a peek" - and then e.g. share the information with their competitor. This did happen before. So how does this work then with MS Office 365 (uploading for example all emails to MS servers will also have some customer data exposed) or running your ERP in a cloud (like all ERP providers are preaching to their customers)? If clauses in contracts are enough to keep you out of legal trouble the same should be true independently of the size of the provider.
- janoc 3y agoYou have to be extremely careful and conscious about what you are able to upload and what you are not. E-mails are generally OK as long as they are not containing customer info (most aren't). The moment you get a data file from the customer (e.g. a CAD drawing, spreadsheet, some analysis, etc.) that is protected by a restrictive NDA, you must not even upload it to the corporate Onedrive to provide it to a colleague. It has to go through an on-premises server - or you have to send someone with an (encrypted) USB stick. And access is strictly controlled, only people who need it will have it. This stuff is taken extremely seriously - a security breach leaking customer data because someone carelessly uploaded a confidential file where they shouldn't have could cost you millions in both lost customers and huge lawsuits. >If clauses in contracts are enough to keep you out of legal trouble the same should be true independently of the size of the provider. The problem is that you are not only after the clause in the contract to "keep you out of legal trouble" and suing the provider for money should anything go wrong. You actually want to be 99.9999% sure that nothing bad happens in the first place, that you have almost 100% uptime and the data are safe, not only to legally cover your backside. Why? Because your own customers (or government) would haul your arse to court otherwise. No amount of compensation you get out of the service provider will fix it should it come to that. You could easily go bankrupt or to prison here. Small startups have no chance to compete in this area with giants like Microsoft or Amazon. E.g. we are in the EU and are legally forbidden from storing some data in US hosted servers. So both Microsoft and Amazon (and also Google) have complied and have EU datacenters for this reason - and you can explicitly specify (both technically and contractually) which instances your e-mail or files are allowed to be stored in and which ones not. An US startup with no own infrastructure only renting servers/compute from e.g. Amazon? How exactly are they going to ensure this, regardless of what is in the contract with me when I have no influence on how they structure their own contracts with their cloud providers? Esp. when that company is here today but may not be tomorrow - goes bust, gets bought out by a competitor, etc. No amount of legalese will protect you here when you have nobody left to sue. Unfortunately in this area the deck is stacked against startups and small companies sky-high, even if you aren't trying to convince them to give you all their confidential data and only trying to sell much more pedestrian services - e.g. payment services or something like payroll management.
- generic92034 3y ago