# company

We're moving our US cluster to dedicated bare metal servers

We're moving Short.io's US cluster from AWS virtual machines to dedicated servers in three Dallas data centers. What it means for where your data lives and who can read it.

Andrii 6 min read #updates #resources #company #guides

We’re moving Short.io’s US cluster off AWS virtual machines and onto dedicated bare metal servers. The new servers are spread across three independent data centers in the Dallas, Texas area, operated by Hivelocity, Limestone Networks and Interserver.

This post is for the people who ask us where customer data lives and who can get to it — legal teams, compliance officers, security reviewers, and anyone who cares about the privacy of their links and analytics. It covers why we’re moving, what changes for your data, and what doesn’t.

Why we’re moving: cost

We’ll be direct about the reason. Renting dedicated servers costs us substantially less than equivalent cloud capacity for a workload like ours, which runs steadily around the clock rather than in unpredictable bursts.

But cost was only the starting point. As we planned the move, three properties of the new setup turned out to matter just as much for our customers’ data.

Dedicated hardware instead of shared hosts

Our AWS instances are virtual machines. A virtual machine is a slice of a physical server, and the other slices on that same server can belong to other AWS customers. The cloud provider’s hypervisor keeps those tenants apart.

On bare metal, each server is dedicated to Short.io. There is no hypervisor shared with other companies and no neighboring tenant running code on the same processor, memory or disks.

Why it matters. Isolation between virtual machines is strong, but it is enforced by software, and hardware-level vulnerabilities have shown that sharing a physical machine carries its own class of risk. A server that runs only Short.io’s workloads removes other tenants from the picture entirely.

Encryption keys that stay with Short.io

Every data-bearing disk in the US cluster is encrypted. Before any customer data reaches one of these servers, we wipe the providers’ preinstalled operating systems and rebuild the machine with full-disk encryption.

The encryption keys are generated and held by Short.io. They are sealed to a security chip inside each server and released only when the machine boots software we have approved and signed. The data center operators do not receive the keys or a passphrase, and they don’t need either to run the hardware.

How that differs from before. On AWS, disk encryption keys are managed through AWS’s own key management service — infrastructure operated by AWS. On our bare metal servers, the keys for data at rest are not shared with anyone outside Short.io.

Where your data lives

Once the migration is complete, US cluster data will be stored and processed in the Dallas, Texas area, across three data centers run by three separate companies:

  • Hivelocity
  • Limestone Networks
  • Interserver

Spreading the servers across three providers means we don’t depend on any single company’s facility, network or terms.

Why Dallas. Our AWS servers are in Northern Virginia, on the East Coast. Dallas sits near the middle of the country, so links will open noticeably faster for visitors on the West Coast, while the East Coast stays only a short hop away. Dallas is also one of the best-connected network hubs in the US, with many carriers and data centers close together.

Independently audited facilities. All three providers operate from Dallas facilities that hold SOC 2 Type II audits, alongside certifications such as PCI DSS and SOC 1 Type II.

Your data and network traffic stay ours

The data center operators supply power, cooling, hardware and an internet uplink. They don’t get access to your data or to our network traffic.

Traffic between our servers travels through encrypted WireGuard tunnels that only Short.io’s servers hold the keys to. We don’t rely on a provider’s private network being private.

Public traffic reaches our servers through encrypted Cloudflare tunnels, and no application or management service is exposed directly to the internet. The data center providers carry only encrypted packets they cannot read.

Backups encrypted before they leave

Backups of the US cluster are stored with Wasabi, a cloud storage provider. We encrypt every backup on our own servers before it is uploaded, with keys that only Short.io holds.

Wasabi stores encrypted data and nothing else. It never receives the keys, so it has no way to decrypt your data — even if it wanted to or were asked to.

What hasn’t changed

Moving to bare metal shifts some responsibilities onto us, and we want to be precise about the boundaries.

Physical custody. The data center operators house and maintain the physical machines. That is exactly why every disk is encrypted and why the keys never leave our control — a removed disk, or a server booted into different software, does not yield readable data.

Cloudflare. Public traffic to Short.io passes through Cloudflare on its way to our servers, as it always has. Cloudflare remains part of our infrastructure and is listed in our privacy policy along with our other providers.

Our compliance program. The move is planned around the controls behind our SOC 2 and ISO 27001 commitments. Encryption at rest is a hard prerequisite — no customer data touches a new server until it is in place.

Our EU cluster. This migration applies to the US cluster only. Our EU cluster continues to run on AWS in Frankfurt, Germany.

For compliance and security reviewers

If you maintain a vendor record for Short.io, the practical updates are the hosting providers, backup provider and locations above — our privacy policy lists them all. If your questionnaire asks about tenancy or key custody, the short answers for the US cluster’s bare metal servers are: single-tenant dedicated hardware, and encryption keys for disks, backups and internal traffic held only by Short.io.

For the engineering side — how we encrypt the disks, unlock them automatically after a reboot, and protect the boot process from tampering — our engineering team wrote a detailed account.