@dalias I host sensitive data on some jurisdictionally appropriate (for threat model) DCs, & for clients (usually NGOs), FDE or with strongly encrypted data partitions on bare metal, a good IDS, & administered over self-hosted VPN. In other cases I host at home or in studio.
Hosting on-prem has its own unique & considerable risks if doing at-risk work, especially if that work is in the jurisdiction you live in.
In such cases better OpSec is to host over the border, in a resistant jurisdiction