Skip to main content

Company / Security

Security and datacenter

Data sovereignty comes down to a few concrete questions: where the data is stored, who can reach it and what the operation depends on. This page answers them.

The datacenter and network sections describe Natron Cloud. On Natron Flex Stack the platform sits in your datacenter and we run it the same way. On Bring Your Own Cloud (Azure, Google Cloud, on-premise) the datacenter belongs to the provider or to you. The platform, access, backup and operations sections apply unchanged, because the same base runs on our AKS and GKE clusters.

The datacenter

Switzerland, own hardware

Natron Cloud runs on servers Natron owns, in a Tier 4 certified Swiss datacenter. No hosting provider sits between you and us.

Redundant power and network

Power feeds, uplinks and switches are redundant. A single component can fail without impact on your workloads.

Network

Default deny between zones

Management, services, customers and the internet are separate zones, and traffic between them is denied unless a rule allows it. Customers never reach each other.

An isolated network per customer

Every customer gets an own network segment behind the firewall.

Platform

Proxmox VE with Ceph

Storage is replicated three ways, HA follows affinity rules, and VMs are live-migrated for maintenance.

Kubernetes hardening

We run upstream Kubernetes with etcd encryption at rest, API audit logging, single sign-on with role-based access and restricted pod security standards.

Encrypted in transit

Traffic between cluster nodes is encrypted, and network policies deny by default.

Runtime and supply chain

Runtime security (Falco), policy enforcement (Kyverno), image scanning, software bills of materials and VM-isolated pods (Kata Containers) are available as managed services on top of any cluster. We support SLSA provenance for your build pipelines and help you introduce it.

Who has access

Named engineers in Switzerland

Only Natron engineers operate the platform. Every login is personal, through single sign-on, with least-privilege roles and audit logging.

No shared passwords, no secrets in code

Access uses personal identities and keys. Secrets are stored encrypted in a secrets manager, and the CI blocks commits that contain them.

Backup and recovery

VMs every night

Every VM is backed up nightly to separate backup servers at a second Swiss location, and we monitor that every job ran. Immutable (WORM) storage is available as an option.

Kubernetes every night

Clusters are backed up nightly with 30 days of retention.

Restore is part of operations

The same team runs restores as ordinary operations tasks, following a documented runbook.

Operations

Everything as code

The infrastructure is defined as code. Every change is reviewed and validated in CI before it reaches production.

Monthly staged patching

Patches go to dev first, then staging, then production. Versions are pinned, and updates need a review before they ship.

Monitoring and on-call

Metrics and logs are retained, alerts reach the on-call engineer around the clock by severity, and a dead-man's switch pages if monitoring itself goes quiet.

Compliance

ISO 27001 and ISO 9001

Natron Tech AG is certified for information security and quality management. Certificates are available on request.

nDSG and GDPR

Data processing under Swiss law. A data processing agreement (AVV/DPA) and the list of sub-processors are available on request.

Swiss company, no foreign parent

Natron Tech AG is owned by its founders and board in Bern. No parent company outside Switzerland can be compelled to hand over your data.

Exit and data return

Open formats

We export VMs as qcow2 or raw images, object data over S3, databases as native dumps; Kubernetes manifests live in your own Git repository.

No technical lock-in

The whole stack is open source: Proxmox, Ceph, upstream Kubernetes, Cilium. What runs here also runs elsewhere.

Sovereignty in four layers

The word means little on its own. Four questions per target make it concrete.

LayerNatron CloudNatron Flex StackBring Your Own Cloud

Ownership

Who owns the hardware and the company?

Natron Tech AG, Bern. No foreign parent.You own the hardware; Natron operates it.The cloud provider or you; Natron operates the platform.

Residency

Where do data and backups live?

Switzerland, two locations: production in one datacenter, backups at a second site.Your datacenter.The region you choose at the provider, or your datacenter.

Operational access

Who can log in?

Named Natron engineers via SSO, least privilege, audited.The same, plus your own staff if you want.Natron engineers via SSO; the provider retains its own platform access.

Technical dependencies

What would we need to replace to leave?

Nothing proprietary: Proxmox, Ceph, upstream Kubernetes.The same.The provider's managed Kubernetes and storage; workloads move via GitOps.

Report a vulnerability

Report vulnerabilities by mail or through our security.txt. We answer within one business day.

Frequently asked questions

Where is my data?

On Natron Cloud: in a Swiss datacenter on hardware Natron owns, with backups at a second Swiss location. On Flex Stack: in your datacenter. On Azure or Google Cloud: in the region you chose.

Who has access to my VMs and clusters?

Named Natron engineers, through single sign-on with least-privilege roles and audit logging. Nobody logs in with shared passwords, and there is no foreign parent company with a legal path to your data.

How do backups work?

Backups live at a second Swiss location, Kubernetes backups keep 30 days of retention, and we monitor every backup job and get an alert when one is missing. Immutable (WORM) storage is available as an option; tell us what your policy requires and we set it up.

Do you use US cloud services in the data path?

Your workloads and data on Natron Cloud stay on our hardware in Switzerland. For ancillary services such as identity management or website tooling, we send you the list of sub-processors on request.

What happens if the datacenter fails?

Natron Cloud runs in one Swiss datacenter. Power, network and storage are redundant, so a single host, disk or switch failure has no impact. If the whole site is lost, we restore from the backups at the second location. For higher requirements we build a second site with you, as Flex Stack or as a stretched setup.

How do I get my data back?

You get VMs as qcow2 or raw images, object data over S3 and databases as native dumps; your Kubernetes manifests already live in your Git. We hand over within the notice period of your contract and confirm deletion afterwards.

Do you support audits and questionnaires?

Yes. We answer security questionnaires, provide ISO certificates and a DPA on request, and join audit calls with your auditor.

Questions about security or a DPA?

We answer security questionnaires, provide a data processing agreement on request and support you in audits.