Summary
- The identity bridge is unusually strong for a small host: the current RIPE record names Johannes Wilhelmus Buurman trading as De Hosting Firma as a Dutch LIR, while SIDN’s live registration record names De Hosting Firma as the registrant of
dehostingfirma.nland as the reseller attached to the domain. - De Hosting Firma exposes a real operating surface—shared hosting, managed virtual and dedicated servers, reseller hosting, domain administration and daily backups—but its public terms make clear that availability, recovery and response guarantees require more precision than the product pages provide.
- The network evidence is substantive rather than decorative. A RIPE allocation record assigns
45.91.122.0/24to the exact trading entity, the prefix is announced through AS39637, and RIPE’s validation service reports a valid route-origin authorisation. Those controls reduce one class of routing risk; they do not answer who can act if the principal cannot. - The decisive purchasing test is recoverability. A customer should require named substitute authority, dual custody for critical access, explicit backup retention and restoration objectives, customer-owned domain registration, an address-space and upstream continuity plan, and a rehearsed exit that does not depend on the usual keyholder being available.
At 02:13, redundancy becomes a question about authority
Imagine a mundane failure rather than a cinematic attack. At 02:13, a storage pool stops serving several managed virtual servers. Monitoring notices. The data centre has power, the upstream network is forwarding packets, the backups may be intact, and the customer’s accounts department has paid every invoice. Yet recovery still requires a sequence of authorised actions: acknowledge the alert, enter the management plane, diagnose the host, decide whether to restore, unlock encrypted material, contact the facility or upstream operator if necessary, update customers, and preserve evidence for any later security or privacy assessment.
The usual hosting brochure describes the equipment in that sequence. It lists redundant feeds, backup systems, fire suppression and monitoring. The more important dependency may be the person who knows which console matters, which password store is current, which customer has an unusual mail configuration, which supplier will accept an urgent instruction, and which change is safe. A technically recoverable service can remain operationally unrecoverable when authority, knowledge and access converge on one unavailable individual.
That is why the exact legal identity matters here. This is not an article about a similarly named Dutch host or an invented umbrella brand. The RIPE NCC member listing and the live RIPE organisation record identify the member as “Johannes Wilhelmus Buurman trading as De Hosting Firma.” The wording identifies a natural person conducting business under a trade name. It does not establish that the business has only one worker. De Hosting Firma’s own pages use plural language about a team and technicians, but do not publish a staff roster, ownership chart, named deputy or succession officer. The evidence therefore supports a narrower and more useful conclusion: the public legal and resource-holding identity is person-centred, while the depth of operational delegation is undisclosed.
That distinction changes the due-diligence question. Headcount is a crude proxy. A sole legal counterparty could have excellent documented delegation, and a much larger company could still concentrate essential privileges in one founder. The issue is whether control can pass cleanly. In hosting, succession is an engineering property before it becomes a probate outcome.
Proving the counterparty before analysing the risk
The public trail joins four elements that are often left disconnected in small-provider research: the person, the trade name, the domain and the Internet-number resources.
First, the live RIPE database response records organisation handle ORG-JWBT1-RIPE, gives the exact name Johannes Wilhelmus Buurman trading as De Hosting Firma, classifies it as a Dutch local Internet registry, and lists Kennemerplein 6 in Haarlem. The organisation record was created in October 2022 and most recently changed in May 2026. A related network-operations role still carries an older Ouderkerk aan de Amstel address. That mismatch is not proof of operational weakness, but it is an early sign that different public records are maintained on different cycles.
Second, SIDN’s authoritative RDAP response records dehostingfirma.nl as active, with an initial registration date of November 26, 2010. It names De Hosting Firma as registrant and shows Registrar.eu as registrar, with De Hosting Firma identified as the reseller. It also reports a signed DNS delegation and three authoritative nameservers under .eu, .com and .org names. This is a current registry-level connection between the brand and its primary Dutch domain, not an inference from a logo.
Third, De Hosting Firma’s published service terms and data-processing terms, dated May 2018, identify the supplier as De Hosting Firma and give Dutch Chamber of Commerce number 37099989. The document uses a historical Amsterdam address and the same telephone number visible in newer records. The current contact page instead gives Kennemerplein 6-14 in Haarlem. The address progression—Amsterdam in the contract, Ouderkerk on several older pages and an operations contact, then Haarlem in current contact and organisation records—supports continuity of the trading identity while exposing a document-control issue.
Fourth, the resource trail reaches beyond a website. The RIPE registration for 45.91.122.0/24 names the exact trading entity as the organisation associated with the allocation. A current routing view shows that prefix originated by AS39637 and described with the same organisation name. This does not make De Hosting Firma the operator of AS39637; rather, it shows a division between the entity holding the allocation and the autonomous system announcing it.
There are limits to the proof. The business says on its about page that it began in 2001, initially alongside website construction, and later made hosting its principal activity. A 2014 DirectAdmin community post signed “Jos, De Hosting Firma” says the host had used the control panel for eight years through another supplier and was seeking control of roughly forty licences. Both are first-person historical accounts, useful for continuity but not equivalent to audited records. The Dutch public KVK search entry point did not yield a current extract in the evidence set, so the present registration particulars should be confirmed from a fresh certified extract before a material contract.
Even with that caveat, the qualification threshold is met. There is enough verifiable history, service detail, registry evidence and live network surface to analyse this exact business. The story is not a generic warning about a tiny host. It is a specific examination of what happens when a person-centred legal identity sits at the centre of several separable but interdependent control systems.
What customers are actually buying
De Hosting Firma’s storefront looks conventional. Its web-hosting offer combines a DirectAdmin control panel with Apache, PHP and MySQL, application installation, mail filtering, free certificates, migration assistance, unlimited traffic subject to fair use and daily server backups. Customers can create and restore manual backups through the panel. The public home page lists annual-contract shared plans from €10.50 to €17.50 a month before VAT, with storage from 2.5GB to 10GB. Those are company-published prices observed on July 18, 2026, not quotations or promises about renewal.
The managed virtual-server offer moves more responsibility toward the provider. The public configurations run from €35.50 a month for a small mail-oriented system to €95.50 for an 8GB, eight-core plan, again on a one-year term before VAT. They include DirectAdmin, monitoring, updates, daily backups and management; root access is available on request. The page lists CloudLinux across the range and adds Imunify360 on larger configurations. Off-site or additional backups are described as available on request rather than as a default property with a stated retention period.
The dedicated-server page advertises configurations from €99 to €199 a month, with management, DirectAdmin, daily backups and full root access. That last pairing is important. “Managed” and “full root” are not incompatible, but together they demand a written responsibility matrix. If a customer changes a firewall, kernel package or mail setting with privileged access, who owns the resulting outage? Who can reverse the change if the customer’s administrator is unavailable? Marketing language cannot allocate that responsibility with enough precision.
The reseller service adds a different form of leverage. It is white-labelled, puts domain registration and package administration in a central dashboard, and keeps De Hosting Firma in the background while the reseller serves end customers under its own name. The public terms reinforce that structure: the reseller contracts in its own name and at its own risk, while De Hosting Firma normally communicates with end customers through the reseller. One inaccessible operator account could therefore affect not just one purchaser but an undisclosed layer of downstream businesses whose users may not know the infrastructure supplier’s name.
The customer is consequently buying much more than CPU time and disk space. The service is a chain of custody for several assets:
- the customer’s content, mailboxes, logs, databases and backups;
- the domain registration, authoritative DNS and the ability to move both;
- application and operating-system administration;
- support knowledge accumulated through tickets and informal conversations;
- billing authority, renewal timing and the commercial relationship with upstream suppliers;
- network identity, including addresses, route authorisation and abuse contacts; and
- the ability to prove who may instruct each external party.
Each component can work while the combined service fails. A server may be healthy while a domain expires. A domain may be renewed while its DNS cannot be changed. A backup may exist while no authorised person can obtain the encryption key. A route may be cryptographically authorised while nobody can ask the upstream to diagnose a fibre or filtering problem. This is why ordinary infrastructure redundancy is necessary but limited public evidence.
Three control planes converge on the keyholder
The operating surface can be divided into three control planes. The division is useful because a continuity plan that covers only one will look reassuring until it is needed.
The customer plane contains the credentials and rights the purchaser can exercise directly: the DirectAdmin login, application administrator accounts, manual backups, perhaps root access, DNS editing and the legal position of the domain registrant. A capable customer can reduce dependency here by keeping current exports, registering domains in its own name, retaining configuration records and ensuring more than one employee can use the panel. De Hosting Firma’s terms place responsibility for actions performed under an account on the customer and tell customers to protect usernames and passwords. That allocation makes customer-side access hygiene a contractual issue, not merely good practice.
The operator plane contains privileges the customer ordinarily cannot see: the server fleet’s management console, hypervisor or rescue access, backup schedules and repositories, monitoring, the master reseller account, the billing system, supplier contracts, abuse handling, support history, and the RIPE portal and maintainer privileges associated with number resources. De Hosting Firma’s product pages make operator work part of the offer through monitoring, updates, migrations, daily backups and personal assistance. The more effective that help is, the more operational knowledge can become tacit rather than captured in a customer-run book.
The upstream plane belongs to other organisations. SIDN maintains the .nl registry; Registrar.eu is the listed registrar for the main domain; BIT supplies the advertised data-centre setting; AS39637 originates the observed address block; and software suppliers underpin control, security and billing functions. Public PeeringDB data for AS39637 identifies the network as ADES BV, also using the NetLogics and i4Networks names. The PeeringDB record for BIT-1 lists AS39637 among networks present at the Ede facility. These operator-contributed directory records corroborate the advertised connection among facility and network entities, but they do not reveal the contracts, escalation rights or account holders linking them.
A routine outage tests technical redundancy inside these planes. Succession tests the authority between them. Can a substitute operator get past multifactor authentication, and is that access pre-authorised rather than improvised? Will a facility accept instructions from that person? Can the billing mandate continue? Can the registrar distinguish a lawful successor from an attacker? Is there a second authorised RIPE contact who can maintain the resource records? Does the customer know whom to call if the normal telephone contact is silent?
The Dutch tax authority’s guidance for the death of an entrepreneur shows the gap between legal and technical continuity. It says heirs settle the tax affairs, may continue the enterprise, and inherit relevant VAT rights and obligations. It also warns that they cannot simply use the deceased person’s DigiD and may need a formal bereavement authorisation. The lesson extends beyond tax access: inheritance can convey rights without conveying usable credentials or immediate recognition by every supplier.
No public source reviewed for this article identifies De Hosting Firma’s substitute decision-maker, emergency operations rota, key escrow procedure or succession exercise. That is not evidence that none exists. It means the buyer cannot price the control from public information. The answer must come from documents, named people and a demonstration.
Hosting economics reward concentration unless buyers price resilience
The economics make this question sharper. At the advertised entry price, one shared-hosting account produces €126 a year before VAT. Against that revenue, the provider promises migration assistance, personal support, a control panel, certificates, filtering, daily backups, infrastructure and administration. The calculation is not a claim about De Hosting Firma’s margins; its costs, utilisation and customer mix are private. It does show why small-hosting economics tend to reward standardisation, automation, shared systems and long customer tenure.
Bespoke attention is affordable when most accounts rarely require it or when higher-value services cross-subsidise the entry tier.
Personal service can be a genuine advantage. De Hosting Firma’s Kiyoh review page displayed a 9.9 rating from twelve reviews, three submitted in the preceding year, with reviewers repeatedly praising fast and personal help. The sample is small, voluntary and hosted on a commercial review platform. It cannot establish average response time, continuity coverage or failure rates. It does illustrate what customers appear to value: direct access to someone who understands the problem.
That value can produce an unusual switching cost. A large provider may have more formal queues but less individual memory. A small provider may resolve a problem because the familiar technician remembers that a legacy application cannot tolerate a new PHP release, or that a particular domain’s mail depends on an old external gateway. The service gets better as knowledge accumulates, while the customer’s ability to leave can get worse if that knowledge is not copied into tickets, configuration inventories and customer-owned documentation.
The public pricing also needs basic verification at purchase. On July 18, the reseller page displayed Business and Expert packages at the same €13.50 monthly price despite different resource allowances. That may be an intentional promotion, a presentation error or an unannounced pricing choice. The service terms exclude obvious typographical errors. A quote should therefore capture storage, account limits, renewal price, term, backup option and support scope rather than relying on a screenshot.
Availability language presents a larger distinction. The home page says the platform recorded 99.9% availability in 2025. Taken as a simple full-year percentage, 0.1% corresponds to about eight hours and forty-six minutes of unavailability. But the public terms say availability is a best-efforts obligation and not guaranteed without a service-level agreement; support response times likewise require a separate agreement. The contact page gives weekday office hours, says messages ordinarily receive an answer within four hours, and reserves the outside-hours telephone line for network outages. These statements can coexist, but only a signed service description can tell a customer which one is enforceable, how availability is measured, what is excluded, and what remedy follows a miss.
For a low-stakes brochure site, that ambiguity may be acceptable. For mail, an online shop, a membership platform or a reseller serving dozens of downstream clients, the economic cost of uncertain recovery can dwarf the annual hosting fee. Cheap hosting is not cheap when the buyer silently assumes a continuity service that was never priced or promised.
Daily backup is not a recovery specification
“Daily backups” appears throughout the offer. It is useful information, but it is not enough to calculate recoverability. A daily job could preserve one copy or ninety. It could reside on the same administrative plane as production or in an independently controlled location. It could be encrypted with a recoverable key or with a secret known to one person. It could include a database and omit a mailbox, or restore a server while leaving DNS, certificates and external integrations broken.
De Hosting Firma’s web-hosting page says daily server backups are intended for server failures and gives customers the option to make and restore their own copies. Its virtual-server page says extra or off-site backup is available on request. The published pages do not state a default retention window, immutable-copy policy, recovery-point objective, recovery-time objective, restore-test frequency, deletion delay or geographic location for each backup tier. Those are missing public specifications, not necessarily missing internal controls.
The terms add consequences that a customer should reconcile before signing. They allow the provider, on termination in stated circumstances, to disable or erase accounts and data immediately without an obligation to give the customer a copy. The data-processing provisions say the customer and end users own personal data, permit subcontractors, and describe deletion when processing ends unless the parties agree otherwise. A termination right, a processor’s deletion duty and a customer’s need for an exit copy can all be legitimate, but their timing must fit together.
The GDPR’s processor contract requirements make the controller’s choice explicit: at the end of services, the processor returns or deletes personal data, unless law requires storage. The same regulation requires measures supporting ongoing confidentiality, integrity, availability and resilience, timely restoration after an incident, and regular testing. Compliance cannot be inferred from the phrase “daily backup”; the controller needs to know what is copied, where, for how long, who can restore it and how the result has been tested.
Independent backup changes the bargaining position. The UK National Cyber Security Centre’s guidance on critical cloud data tells organisations to export essential information, know how to restore it and keep a copy somewhere separate from the service. That advice is particularly apt for a person-centred counterparty. A provider-controlled backup protects against disk failure. A customer-controlled copy protects against provider unavailability, account suspension, a commercial dispute, a corrupted management plane and an unsuccessful succession.
A serious buyer should ask for a live restoration exercise, not a policy answer. Select a non-production site with a database, mail, certificate and scheduled task. Restore it into an isolated destination. Record the oldest recoverable point, elapsed time, missing elements, people required and credentials used. Then repeat the exercise without the usual operator participating. If the second test cannot begin, the most important backup dependency has been found.
Domains and address space have their own succession clocks
Servers are movable; names and addresses make the move reachable. De Hosting Firma’s service combines both, and each follows an external governance process.
SIDN says in its guidance for registrants that the recorded registrant controls important acts such as transfer and conveyance, and that a business should be registered under its correct name. Its transfer procedure says the existing registrar should provide the required authorisation code within five days. If a registrar goes out of business, the registrant can work through a new registrar and SIDN’s special procedure. The general terms for .nl registrants further provide a period for appointing a replacement when a registrar relationship ends.
The live RDAP record is encouraging for De Hosting Firma’s own domain: the registrant is the brand, the registrar is separately identified, and the delegation is signed. For customers, the essential question is whether their names are registered to them, with current contacts they can access, rather than to the reseller for administrative convenience. De Hosting Firma’s terms acknowledge that the provider acts as an intermediary for domain and address requests and say it will cooperate with transfer where a domain has been put in its own name for the customer. A buyer should not wait for a crisis to discover which pattern applies.
An annual domain-recovery drill is simple. The customer obtains the registry record, confirms its own legal name and reachable contacts, requests the transfer authorisation without completing the move, verifies that two customer employees can access the DNS zone, and exports the records. The drill should also inventory names registered through other suppliers, certificate validation paths and any domain used for the hosting provider’s own login or password recovery. Circular dependency is common: if the only recovery mailbox is hosted on the system being recovered, formal ownership may not produce timely access.
Internet address resources add a less familiar layer. The 45.91.122.0/24 allocation record ties a block of 256 IPv4 addresses to the exact trading entity. The current route is originated by AS39637, while RIPE’s RPKI check reports a valid authorisation for that origin and prefix length. This is a positive control: networks that perform route-origin validation can reject conflicting invalid announcements. It does not provide a second operator, preserve a commercial transit contract or grant a successor access to the RIPE portal.
RIPE’s resource-transfer process shows why formal preparation matters. Transfers require documented parties, agreements and proof of authorised signatories; a natural person may need identity documentation. Some changes in business structure or control therefore need an administrative process even when the packets are still flowing. A successor who first learns the organisation handle during an emergency is already late.
The purchasing questions are concrete. Who besides the principal has authorised access to the member portal and maintainer process? Which addresses are assigned to which customers? Does a customer receive portable provider-independent space, or ordinary addresses that must change on exit? What is the renumbering plan and expected DNS time-to-live? Which upstream contract causes AS39637 to originate the block, and what happens to that route if the trading counterparty changes? RPKI can authenticate the approved origin; it cannot answer any of those commercial and human questions.
Dutch location is a property of the chain, not a slogan
De Hosting Firma says its servers are in the Netherlands at BIT and that customer data is not transferred outside the European Union. The technology and network page describes redundant power, generators, fire suppression, physical access controls and round-the-clock monitoring at the facility. The claims are plausible and partly corroborated by independent operational records, but they need careful attribution.
BIT’s own data-centre factsheets describe redundant feeds, separate uninterruptible power systems, generator capacity, Argonite fire suppression and certifications including ISO 27001, ISO 9001 and NEN 7510. BIT’s ISO 27001 statement of applicability defines a scope covering BIT’s data-centre and Internet services. PeeringDB places the relevant upstream network at BIT-1. Together, those sources support a physical and network locality story. They do not show that De Hosting Firma itself holds BIT’s certifications, that every product uses the same building, or that every administrative and backup operation stays there.
Data sovereignty is wider than rack location. A customer must map production storage, backup storage, monitoring, support access, mail filtering, certificate issuance, domain registration, billing, ticketing and any remote administration. It must distinguish where data is stored from where people can access it and which law can compel each supplier. The contract’s subprocessor provisions matter as much as the server’s postcode.
Here the public documents contain a tension. Current marketing says there is no transfer outside the European Union. The May 2018 data-processing terms contemplate processing inside or outside the EU subject to applicable requirements. The older wording does not prove that any current transfer occurs, and the newer statement may reflect a changed supply chain. A buyer should ask for the current processing agreement, subprocessor list, service-by-service locations and transfer mechanism rather than choose whichever public sentence is more convenient.
Regulatory expectations are also moving. The Dutch government announced on July 7 that the Cyberbeveiligingswet will take effect on August 15, 2026. The law will bring registration, care, incident-reporting, governance and supervision duties for covered organisations. The Dutch NCSC’s current scope explanation gives domain-registration services a special position and warns that scope and duties vary by type and size. The public evidence does not establish De Hosting Firma’s final classification. It does establish that customers will increasingly ask suppliers for business-continuity, supply-chain and incident evidence whether or not a particular supplier falls into every statutory duty.
Public-sector policy offers a useful benchmark without becoming a private-sector rule. The Dutch government’s revised cloud policy of July 3, 2026 requires exit plans for important cloud services and calls for explicit consideration of concentration and foreign-law risks. An SME need not reproduce central-government paperwork. It can adopt the same underlying discipline: know how to leave before dependence becomes urgent.
Good technical signals do not replace governance evidence
The public record contains meaningful positive signals. The main domain has a signed DNS delegation. The address block is specifically registered to the trading entity. Its observed origin is covered by a valid RPKI authorisation. The advertised facility has a substantial independently documented security and resilience programme. The product pages disclose major software components and distinguish shared, managed virtual and dedicated services.
Those facts are more valuable than generic “enterprise-grade” language. They show that De Hosting Firma participates in real registry and routing processes and has made choices that reduce domain-tampering and route-leak risk. Yet each control protects a bounded layer. DNSSEC authenticates signed DNS data; it does not ensure that an authorised but mistaken operator cannot change a record. RPKI validates the relationship between a prefix and an origin AS; it does not restore a server or pay a supplier. A certified facility controls its own scope; it does not certify every tenant’s software, staffing or succession procedure.
The responsibility boundary is especially important on managed systems. The terms make customers responsible for activity performed through their account. The dedicated offer gives full root access while also promising management. The virtual offer provides root on request. A defensible contract should allocate at least operating-system patching, control-panel updates, application updates, malware response, firewall changes, privileged-account review, log retention and emergency intervention. “Managed” should be a table of acts and response obligations, not an adjective.
Public-document hygiene provides a softer but relevant signal. The SSL information page still refers to the former Dutch Personal Data Protection Act and an old maximum fine. The Dutch government’s GDPR implementation guide records that the GDPR has applied since May 25, 2018, replacing the old framework. Several product pages still show the Ouderkerk address, the 2018 contract shows Amsterdam, and current contact records show Haarlem. The privacy-location wording differs between old contractual and current marketing documents.
None of that demonstrates a security incident or unlawful processing. It demonstrates that public promises and legal documents have aged at different speeds. For a service whose continuity depends on accurate registrant contacts, escalation paths and authority records, document maintenance is itself a control worth testing. Ask the supplier to identify the current binding terms, date them, archive the superseded version and reconcile the location and privacy statements.
The incident record is mostly an evidence gap
No verified public incident chronology for the exact business was identified in the frozen source set. That sentence must not be inverted into “there have been no incidents.” Small providers are rarely subject to the continuous public scrutiny applied to listed cloud companies, and outages may be resolved through private tickets without a public status archive.
The company reports 99.9% availability for 2025 and customer reviews are strongly positive, but neither supplies the denominator a risk manager needs. The availability figure does not publish its measurement point, exclusions, longest incident, affected services or calculation method. Twelve voluntary reviews say little about tail risk. A fast reply to a routine configuration problem is not evidence that a second authorised operator can recover a management plane during the principal’s absence.
The published support window is specific enough to plan around: weekdays during office hours, with the phone outside those hours reserved for network outages. It is not a public commitment to round-the-clock application, mail, domain or account recovery. Customers should decide whether that boundary matches their own incident profile. An online store may care most about an application failure on Saturday evening; a mail-dependent consultancy may regard an account lockout as critical even while the network is healthy.
The right due-diligence request is proportionate. Ask for a twelve-month incident summary with dates, broad cause categories, customer impact and time to restore; an explanation of how availability is measured; and evidence from the most recent continuity exercise. Sensitive technical details can be redacted. A provider that cannot disclose a public history may still show a controlled record under confidentiality. Silence should lead to a question, not an accusation.
Switching costs grow in the spaces between products
De Hosting Firma reduces the immediate cost of entry with migration help, bundled certificates, a familiar panel and direct support. The same bundle can increase the cost of exit. Hosting, mail, DNS, domain renewal, backups, security tooling and support knowledge become one operational relationship. A customer moving only the website may overlook mail routing, scheduled tasks, database versions, certificate renewal, DNSSEC, outbound-mail reputation, archived tickets or the domain contact used for approval.
Reseller customers carry an additional complication. Their end clients may believe the reseller is the complete supplier, while De Hosting Firma operates the underlying service and domain workflow. If the reseller leaves, fails or cannot reach the provider, the end customer’s contractual and technical routes may diverge. If De Hosting Firma itself cannot act, one interrupted control plane can propagate through several commercial layers. The public terms correctly distinguish the reseller’s responsibility, but the end-to-end recovery path still needs testing.
Competitors demonstrate that backup and exit parameters can be made more explicit in ordinary consumer-facing offers. TransIP’s web-hosting page advertises hourly recovery points retained for thirty days and monthly cancellation. Antagonist’s comparison page publishes a range of retained backup points and says there is no notice period. These are supplier claims, not proof that either service is superior, and their packages are not perfectly comparable. They show that retention and exit terms are marketable product attributes rather than details that must remain unknowable.
The best counterweight to switching cost is not frequent switching. It is a maintained ability to switch. The customer should hold an inventory of domains, zones, databases, mailboxes, certificates, scheduled tasks, versions, privileged accounts, address dependencies and third-party integrations. It should export data at an agreed interval and test a partial move. The test gives both parties better information: the customer learns its real dependencies, and the provider can fix documentation before an emergency.
A procurement test designed for this operating surface
A generic security questionnaire will miss the keyholder problem because it asks whether a control exists, not whether control can pass to another authorised person. A prospective or renewing customer should make the following checks part of the commercial decision.
1. Establish the legal and trading identity. Obtain a current certified KVK extract for number 37099989, confirm the exact contracting name and trade name, and reconcile the Haarlem, Ouderkerk and Amsterdam addresses across public documents. Confirm who may sign, who owns customer obligations if the principal is unavailable, and what notice will be given if the business form or control changes. This is identity assurance, not curiosity.
2. Name the continuity roles. Ask for the role—not necessarily the private personal details in a public document—of the substitute incident lead, the person with access to finance and supplier accounts, and the person authorised to communicate with customers. Confirm that at least two people can perform each critical act and that substitutes periodically exercise the access. The NCSC’s small-organisation incident guidance recommends sharing incident responsibility so absence does not halt response.
3. Demonstrate access recovery. In a controlled session, have the usual operator stand aside. Let the authorised substitute receive an alert, enter the management environment, locate the affected service, retrieve the current run book, contact an upstream and issue a customer update. Confirm that emergency credentials are protected, audited and independent of mail or devices that may fail in the same incident. Do not ask to see secrets; ask to see the process work.
4. Separate customer and supplier authority. List every control the customer can exercise without provider intervention: panel access, root access where contracted, DNS changes, domain transfer, data export and backup restore. List the provider-only controls beside them. For each provider-only control, identify a substitute and an exit route. Ambiguity over a single privileged action can determine the recovery time of the whole service.
5. Verify every domain registration. Use registry records to confirm that the customer is the registrant, that contacts reach customer-controlled addresses, and that no recovery path depends exclusively on the hosted domain. Obtain a practice transfer authorisation, export DNS zones and document DNSSEC handling. Where De Hosting Firma appears as registrant for a customer name, require a correction or a written custody and transfer arrangement before the domain becomes critical.
6. Map Internet-number and upstream dependencies. Ask which services use addresses from 45.91.122.0/24, which are behind shared translation or filtering, and which customers would need renumbering on exit. Document the relationship with AS39637, the route-origin authorisation, the facility contract and the authorised RIPE contacts. Require a procedure for death, incapacity, sale and change of business structure. A route can continue during a legal transition, but that grace period should not be mistaken for a plan.
7. Turn “daily backup” into measurable recovery. Record scope, frequency, retention, location, encryption, deletion delay, immutability, monitoring and restore-test results for each service. Set recovery-point and recovery-time objectives. State whether the standard copy is off-site and whether it uses an administrative boundary independent of production. Keep a customer-controlled export. Then restore without the normal operator.
8. Fix the managed-service boundary. Define responsibility for the operating system, control panel, runtime, database, mail stack, malware tooling, application, firewall, privileged users, logs and emergency changes. If the customer has root, state how that affects support and restoration. If the provider may intervene, state what approval and evidence are required. This prevents a continuity exercise from becoming a dispute over who was supposed to act.
9. Ask for supplier and locality evidence. Request the current processing agreement, subprocessor list, service locations, remote-access countries, backup locations and transfer safeguards. Attribute BIT’s certifications to BIT’s scope and ask what controls De Hosting Firma adds above the facility. Verify which product variants actually run at BIT. The NCSC’s supplier-assurance questions offer a practical structure for ownership, incident response, continuity, offshoring and independent testing.
10. Contract for communication and service levels. Define severity, support channels, coverage hours, first-response targets, update frequency, restoration targets, measurement, exclusions and remedies. State whether an application, mailbox, domain or account-access failure qualifies for outside-hours escalation even when the network remains up. Ask for a status channel hosted outside the primary infrastructure and for substitute authority to publish to it.
11. Reconcile termination with data return. Set an export window, format, assistance rate, final backup, deletion schedule and evidence of deletion. Prevent immediate account removal from defeating the controller’s choice to receive its data. Cover insolvency, incapacity and disputed invoices as well as an orderly cancellation. Decide how downstream reseller customers can obtain essential data if their direct reseller cannot act.
12. Test billing continuity. Inventory supplier renewals for domains, licences, racks, connectivity and security services. Confirm that a substitute can see due dates and make authorised payments without using a personal bank login. For the customer, ensure invoices reach more than one contact and that an expired card cannot silently disable a critical service. Operational continuity often fails through an ordinary unpaid renewal rather than a hardware fault.
13. Price the residual risk. If dual coverage, off-site backup, a service-level agreement or an assisted exit costs extra, obtain the price. The answer may still favour De Hosting Firma: a responsive specialist with a clear continuity addendum can be a better fit than an opaque larger platform. The purpose is to stop treating unpurchased resilience as if it were included in a low monthly fee.
14. Repeat the exercise annually. People, addresses, suppliers and systems change. The stale addresses and legacy privacy wording visible in the current public estate show why a one-time questionnaire decays. Recheck registry contacts, restore a sample, exercise substitute access, export the dependency inventory and close the findings with dates and owners.
Passing this test does not require De Hosting Firma to publish sensitive access arrangements. It requires enough inspectable evidence for the customer to know that absence of the familiar keyholder will not freeze the service. A confidential demonstration, independent assurance report or witnessed exercise can protect security while proving recoverability.
The verdict: viable evidence, unresolved succession
The exact business has enough operating substance for a specific assessment. The domain record, terms, current contact details, RIPE membership, address allocation, upstream route and product catalogue join into a coherent counterparty. The public evidence supports a long-lived Dutch hosting trade with a genuine role in domain resale and Internet-resource administration. It also supports several positive technical choices, including DNSSEC and a valid route-origin authorisation.
What it does not support is the assumption that personal service automatically includes institutional continuity. The legal identity centres on a natural person. The public site does not name a substitute authority. Daily backup lacks a public recovery specification. Facility assurances belong to the facility’s scope. Old and new documents disagree on addresses and the possibility of processing outside the EU. Availability is marketed, while enforceable guarantees depend on a separate agreement. None of these gaps proves failure; together they define the work a serious customer must complete.
The watchpoints are observable. Look for a refreshed contract and processing agreement; one consistent address; a named continuity role; explicit backup retention and restore objectives; a public or confidential incident history; clearer service-level terms; a current subprocessor and locality schedule; and evidence that a second authorised person can operate the domain, RIPE, supplier, billing and recovery paths. Watch the prefix’s origin and RPKI status, but do not mistake stable routing for stable governance. Ask reseller customers to trace their own end-customer recovery route.
De Hosting Firma’s scale can be an advantage when the person answering understands the whole stack. It becomes a concentration risk only when that understanding cannot be transferred. The most important redundancy is therefore not another disk or diesel generator. It is another authorised, practised route from alarm to recovery—one that works when the person whose name anchors the business cannot turn the key.

