CurNext

CurNext

EU cloud, anchored in Germany

Application hosting on Hetzner in Germany. Database and authentication on Supabase in Frankfurt. Public traffic protected at the Cloudflare edge and distributed across load-balanced replicas.

This page explains where CurNext runs for EU buyers, IT, and procurement. It is not a status dashboard or a public inventory of machines.

Where workloads run

Not a multi-cloud story. EU production residency is Germany / Frankfurt as stated below - we do not invent a second production country here.

  • Application origins

    Hetzner

    Germany

    CurNext application containers for EU users run on Hetzner infrastructure in Germany.

    Runs: Docker images for marketing, web SaaS, API, and related app containers as deployed

  • Database + Auth

    Supabase

    Frankfurt, Germany

    PostgreSQL and Auth for the product run on Supabase in Frankfurt, Germany.

    Runs: PostgreSQL, Supabase Auth

  • Edge / CDN / WAF

    Cloudflare

    Global edge

    DNS, TLS, WAF, and CDN sit in front of origins so only healthy, load-balanced replicas serve traffic.

    Runs: DNS, TLS, WAF, CDN, Turnstile on public forms

Cloudflare R2

EU jurisdiction option

When object storage is used, uploads and BIM/plan files can use Cloudflare R2 with an EU jurisdiction option, including optional GDPR audit archive.

How traffic flows

Public HTTPS terminates and is filtered at Cloudflare. App tiers scale as stateless Docker replicas behind load balancers in Germany.

  1. 01Internet
  2. 02Cloudflare (DNS, TLS, WAF, CDN)
  3. 03Load balancer(s)
  4. 04Docker replicas on Hetzner (Germany)
  5. 05Supabase Postgres + Auth (Frankfurt, Germany)

Health checks use GET /api/health (marketing) and API health routes so load balancers only send traffic to healthy replicas.

Publishable hosts

What we store where

Core application and database for EU users are hosted in Germany. Some third-party services (for example email SMTP, Stripe billing, or Cloudflare edge caches) sit outside that residency boundary - see the privacy policy for details.

Where CurNext stores and processes data by layer
LayerWhereNote
App computeHetzner, GermanyStateless Docker replicas for marketing, SaaS web, and API
Database + AuthSupabase, FrankfurtPostgreSQL and product authentication
Object storageCloudflare R2, EU optionUploads and BIM/plan files when configured
Edge cache / WAFCloudflare global edgeTLS termination, WAF, CDN in front of origins
Field devicesSite edge (L1-L4)Telemetry processed on site; cloud is L5. Sensors do not store customer PII in Hetzner

Scale and reliability posture

The stack is production-shaped: load balancers, health probes, and stateless replicas. We do not publish replica counts, RPS, or uptime percentages here.

  • Web / marketing

    Stateless containers; N replicas behind a load balancer

  • API

    Stateless API replicas; health probes for the load balancer

  • Worker

    Queue workers can add replicas as load grows

  • Database

    Managed Supabase; the app uses a pooler for many replicas

  • Sessions

    Supabase cookies - no sticky session requirement on the load balancer

Privacy and contact

CurNext is registered in Helsinki, Finland. The platform is designed for EU operation with GDPR-oriented controls such as audit logging, RBAC, and invite-only access.

  • - Legal entity: CurNext, Helsinki, Finland
  • - Core application and database for EU users: Germany / Frankfurt
  • - Customers inherit provider controls from Hetzner, Supabase, and Cloudflare at the infrastructure layer - review those vendors' public trust pages for their certifications
  • - CurNext does not claim ISO 27001 or SOC 2 for itself on this page

[email protected]

Translations are provided for convenience. Where a signed agreement exists, the English instrument controls.