The SAFOZI cloud platform adopts a multi-layered security model. This allows customers to customize security measures at the network, hypervisor, and cloud server levels.
SAFOZI’s physical server virtualization architecture provides the foundation for a secure cloud service by ensuring the separation of cloud server operating systems from hypervisors. Compared to the “container-based virtualization” approach, this method is more reliable, as it avoids the sharing of operating system components between cloud servers and physical servers. On the SAFOZI Cloud Platform, an attack targeting the physical servers’ operating systems has no direct impact on clients’ cloud servers.
The Customer Isolation Module (CIM) has three main functions:
Secure VLAN:
The CIM enables secure VLAN sharing across multiple cloud servers and manages multiple VLANs and their associated IP addresses on the platform.
Private VLAN:
With the CIM, each client enjoys complete security within their section of the platform. The platform provides private VLAN security at no additional cost.
CIM Firewall:
The CIM provides an additional firewall layer at the hypervisor level.
The SAFOZI platform features four layers of firewall protection by default. This includes firewalls at the network level, on the hypervisors, and on each cloud server. Naturally, this is further secured by additional firewall tools:


firewall tools installed on the network, the equipment, and the data center.


The platform also offers a wide range of firewalls and security services installed on the hypervisor platforms to ensure complete separation of cloud servers and their data.


A unique technology—part of the CIM module and specific to OnApp users—is installed on the hypervisors. It serves as an additional protection layer against tampering and packet sniffing, ensuring that no cloud server interacts with another.


The final layer is a client-side firewall. Firewall configuration is managed via the client area for each cloud server. Each server can be configured to accept or block traffic from IP addresses specified by the client.