I realize that is vague, but it's a bit of a difficult thing to discuss without exposing private data. If I so much as say "Just don't do X" then I'm effectively saying Client A did X. Tough waters to navigate.
I hope that helps a bit at least.
At least in Tokyo I know plenty of people who are running PG on DO in a docker instances and just doing backups on DO cause its cheaper than something like heroku managed PG so if I was one of them (I kept my data layer off of DO) I would be completely destroyed by this. So I tell everyone I know now at meetups about this experience and so happy to share specific details.
They told me I log on from multiple locations (OMG I have a laptop and work while I travel, busted) and that I had a gmail address on my account.
The most agregious thing is that if their trigger happy "security and trust" flagger flags you, there is no warning where they reach out to you, they just destroy your instances, don't tell you about that either until you logon and are asked to file a ticket if you want your account unlocked...then a month later will unlock it for you but everything nuked.
(1) Gitlab/Github for source code (almost free)
(2) automysqlbackup (or similar) to an S3 bucket for your database (very cheap) using S3FS
(3) Make sure you have a way to reproduce your entire server environment using fabric, ansible, chef, puppet (or Docker images) that is also in source control
If you have PROD code, this is normally called DR (Disaster Recovery)