Skip to main content

Company / Security

Security and datacenter

Data sovereignty comes down to a few concrete questions: where the data is stored, who can reach it and what the operation depends on. This page answers them.

The datacenter and network sections describe Natron Cloud. On Natron Flex Stack the platform sits in your datacenter and we run it the same way. On Bring Your Own Cloud (Azure, Google Cloud, on-premise) the datacenter belongs to the provider or to you. The platform, access, backup and operations sections apply unchanged, because the same base runs on our AKS and GKE clusters.

The datacenter

Switzerland, own hardware

Natron Cloud runs on servers Natron owns, in an ISO 27001 certified Swiss datacenter. No hosting provider sits between you and us.

Redundant power and network

Power feeds and uplinks are redundant. The switch fabric uses LACP bonds and MLAG, so a single link or switch can fail without impact.

Refreshed hardware

The compute fleet was replaced in 2025 with current AMD CPUs and NVMe storage; older hosts serve as dedicated backup servers.

Network

Default deny between zones

The network has four zones (management, services, customers, internet) with a written flow matrix. Customers never talk to each other, and the management plane accepts no inbound connections.

A VLAN zone per customer

Every customer gets an own zone and vnet in Proxmox SDN behind a FortiGate firewall with separate virtual domains.

Dual-stack IPv6 and BGP

Most environments run native IPv6, and Kubernetes load-balancer addresses are announced over BGP.

Swiss defaults

Time comes from the Swiss NTP pool, names resolve through Quad9.

Platform

Proxmox VE with Ceph

Storage is replicated three ways with compression, HA follows affinity rules, and VMs are live-migrated for maintenance.

Kubernetes hardening

We run upstream Kubernetes with etcd encryption at rest, API audit logging, RBAC through Entra ID SSO and Pod Security Standards "restricted".

Encrypted in transit

Cilium encrypts traffic between nodes with WireGuard and enforces default-deny network policies (370+ policies across the fleet).

Runtime and supply chain

Falco watches the runtime, Kyverno enforces policies, images are pulled only through a private Harbor mirror with Trivy scanning, and SBOMs are tracked in Dependency-Track. Kata Containers isolate pods in VMs where needed.

Who has access

Named engineers in Switzerland

Only Natron engineers operate the platform. Every login goes through Entra ID with a least-privilege operator role on Proxmox and Kubernetes.

Keys, not passwords

SSH accepts only hardware-backed keys and runs fail2ban. OpenVPN uses TLS 1.3 with OIDC login, and Teleport handles zero-trust access to clusters and databases.

Secrets stay encrypted

Inventories are vault-encrypted, gitleaks runs in CI, application secrets live in OpenBao with automatic unseal.

Backup and recovery

VMs every night

VMs are backed up every night to dedicated Proxmox Backup Servers with deduplication and staggered windows. The backups are encrypted, and we monitor their freshness.

Kubernetes every night

Velero writes backups with 30-day retention to S3-compatible storage. etcd gets nightly snapshots and a monthly defragmentation.

Restore is part of operations

The same team runs restores as ordinary operations tasks, following a documented runbook.

Operations

Everything as code

We use Ansible for the virtualisation layer, Terraform for hyperscaler environments and Flux GitOps for Kubernetes. Every change is reviewed and validated in CI.

Monthly staged patching

Patches go to dev first, then staging, then production. Kernels and packages are pinned, and dependency updates wait at least seven days and need manual approval.

449 alert rules

Prometheus, Grafana and Loki keep metrics for 50 days and logs for 30 days. Alerts reach on-call as P1, P2 or P3, and a dead-man's-switch pages if monitoring itself goes quiet.

Privacy by default

End-user identities in monitoring are pseudonymised unless a customer explicitly needs them.

Compliance

ISO 27001 and ISO 9001

Natron Tech AG is certified for information security and quality management. Certificates are available on request.

nDSG and GDPR

Data processing under Swiss law. A data processing agreement (AVV/DPA) and the list of sub-processors are available on request.

Swiss company, no foreign parent

Natron Tech AG is owned by its founders and board in Bern. No parent company outside Switzerland can be compelled to hand over your data.

Exit and data return

Open formats

We export VMs as qcow2 or raw images, object data over S3, databases as native dumps; Kubernetes manifests live in your own Git repository.

No technical lock-in

The whole stack is open source: Proxmox, Ceph, upstream Kubernetes, Cilium. What runs here also runs elsewhere.

Sovereignty in four layers

The word means little on its own. Four questions per target make it concrete.

LayerNatron CloudNatron Flex StackBring Your Own Cloud

Ownership

Who owns the hardware and the company?

Natron Tech AG, Bern. No foreign parent.You own the hardware; Natron operates it.The cloud provider or you; Natron operates the platform.

Residency

Where do data and backups live?

Switzerland, one datacenter, backups on separate servers.Your datacenter.The region you choose at the provider, or your datacenter.

Operational access

Who can log in?

Named Natron engineers via SSO, least privilege, audited.The same, plus your own staff if you want.Natron engineers via SSO; the provider retains its own platform access.

Technical dependencies

What would we need to replace to leave?

Nothing proprietary: Proxmox, Ceph, upstream Kubernetes.The same.The provider's managed Kubernetes and storage; workloads move via GitOps.

Report a vulnerability

Report vulnerabilities to support@natron.io or through our security.txt. We answer within one business day.

security.txt

Frequently asked questions

Where is my data?

On Natron Cloud: in a Swiss datacenter on hardware Natron owns, with backups on separate Proxmox Backup Servers. On Flex Stack: in your datacenter. On Azure or Google Cloud: in the region you chose.

Who has access to my VMs and clusters?

Named Natron engineers, through Entra ID single sign-on with least-privilege roles and audit logging. Nobody logs in with shared passwords, and there is no foreign parent company with a legal path to your data.

Are backups encrypted?

VM backups on Proxmox Backup Server are encrypted. Kubernetes backups go to S3-compatible storage with 30 days of retention. We monitor the freshness of every backup job and get an alert when one is missing.

Do you use US cloud services in the data path?

Your workloads and data on Natron Cloud stay on our hardware in Switzerland. For ancillary services such as identity management or website tooling, we send you the list of sub-processors on request.

What happens if the datacenter fails?

Natron Cloud runs in one Swiss datacenter. Power, network and storage are redundant, so a single host, disk or switch failure has no impact. If the whole site is lost, we restore from backups. For higher requirements we build a second site with you, as Flex Stack or as a stretched setup.

How do I get my data back?

You get VMs as qcow2 or raw images, object data over S3 and databases as native dumps; your Kubernetes manifests already live in your Git. We hand over within the notice period of your contract and confirm deletion afterwards.

Do you support audits and questionnaires?

Yes. We answer security questionnaires, provide ISO certificates and a DPA on request, and join audit calls with your auditor.

Questions about security or a DPA?

We answer security questionnaires, provide a data processing agreement on request and support you in audits.