Company / Security
Security and datacenter
Data sovereignty comes down to a few concrete questions: where the data is stored, who can reach it and what the operation depends on. This page answers them.
The datacenter and network sections describe Natron Cloud. On Natron Flex Stack the platform sits in your datacenter and we run it the same way. On Bring Your Own Cloud (Azure, Google Cloud, on-premise) the datacenter belongs to the provider or to you. The platform, access, backup and operations sections apply unchanged, because the same base runs on our AKS and GKE clusters.
The datacenter
Switzerland, own hardware
Natron Cloud runs on servers Natron owns, in an ISO 27001 certified Swiss datacenter. No hosting provider sits between you and us.
Redundant power and network
Power feeds and uplinks are redundant. The switch fabric uses LACP bonds and MLAG, so a single link or switch can fail without impact.
Refreshed hardware
The compute fleet was replaced in 2025 with current AMD CPUs and NVMe storage; older hosts serve as dedicated backup servers.
Network
Default deny between zones
The network has four zones (management, services, customers, internet) with a written flow matrix. Customers never talk to each other, and the management plane accepts no inbound connections.
A VLAN zone per customer
Every customer gets an own zone and vnet in Proxmox SDN behind a FortiGate firewall with separate virtual domains.
Dual-stack IPv6 and BGP
Most environments run native IPv6, and Kubernetes load-balancer addresses are announced over BGP.
Swiss defaults
Time comes from the Swiss NTP pool, names resolve through Quad9.
Platform
Proxmox VE with Ceph
Storage is replicated three ways with compression, HA follows affinity rules, and VMs are live-migrated for maintenance.
Kubernetes hardening
We run upstream Kubernetes with etcd encryption at rest, API audit logging, RBAC through Entra ID SSO and Pod Security Standards "restricted".
Encrypted in transit
Cilium encrypts traffic between nodes with WireGuard and enforces default-deny network policies (370+ policies across the fleet).
Runtime and supply chain
Falco watches the runtime, Kyverno enforces policies, images are pulled only through a private Harbor mirror with Trivy scanning, and SBOMs are tracked in Dependency-Track. Kata Containers isolate pods in VMs where needed.
Who has access
Named engineers in Switzerland
Only Natron engineers operate the platform. Every login goes through Entra ID with a least-privilege operator role on Proxmox and Kubernetes.
Keys, not passwords
SSH accepts only hardware-backed keys and runs fail2ban. OpenVPN uses TLS 1.3 with OIDC login, and Teleport handles zero-trust access to clusters and databases.
Secrets stay encrypted
Inventories are vault-encrypted, gitleaks runs in CI, application secrets live in OpenBao with automatic unseal.
Backup and recovery
VMs every night
VMs are backed up every night to dedicated Proxmox Backup Servers with deduplication and staggered windows. The backups are encrypted, and we monitor their freshness.
Kubernetes every night
Velero writes backups with 30-day retention to S3-compatible storage. etcd gets nightly snapshots and a monthly defragmentation.
Restore is part of operations
The same team runs restores as ordinary operations tasks, following a documented runbook.
Operations
Everything as code
We use Ansible for the virtualisation layer, Terraform for hyperscaler environments and Flux GitOps for Kubernetes. Every change is reviewed and validated in CI.
Monthly staged patching
Patches go to dev first, then staging, then production. Kernels and packages are pinned, and dependency updates wait at least seven days and need manual approval.
449 alert rules
Prometheus, Grafana and Loki keep metrics for 50 days and logs for 30 days. Alerts reach on-call as P1, P2 or P3, and a dead-man's-switch pages if monitoring itself goes quiet.
Privacy by default
End-user identities in monitoring are pseudonymised unless a customer explicitly needs them.
Compliance
ISO 27001 and ISO 9001
Natron Tech AG is certified for information security and quality management. Certificates are available on request.
nDSG and GDPR
Data processing under Swiss law. A data processing agreement (AVV/DPA) and the list of sub-processors are available on request.
Swiss company, no foreign parent
Natron Tech AG is owned by its founders and board in Bern. No parent company outside Switzerland can be compelled to hand over your data.
Exit and data return
Open formats
We export VMs as qcow2 or raw images, object data over S3, databases as native dumps; Kubernetes manifests live in your own Git repository.
No technical lock-in
The whole stack is open source: Proxmox, Ceph, upstream Kubernetes, Cilium. What runs here also runs elsewhere.
Sovereignty in four layers
The word means little on its own. Four questions per target make it concrete.
| Layer | Natron Cloud | Natron Flex Stack | Bring Your Own Cloud |
|---|---|---|---|
Ownership Who owns the hardware and the company? | Natron Tech AG, Bern. No foreign parent. | You own the hardware; Natron operates it. | The cloud provider or you; Natron operates the platform. |
Residency Where do data and backups live? | Switzerland, one datacenter, backups on separate servers. | Your datacenter. | The region you choose at the provider, or your datacenter. |
Operational access Who can log in? | Named Natron engineers via SSO, least privilege, audited. | The same, plus your own staff if you want. | Natron engineers via SSO; the provider retains its own platform access. |
Technical dependencies What would we need to replace to leave? | Nothing proprietary: Proxmox, Ceph, upstream Kubernetes. | The same. | The provider's managed Kubernetes and storage; workloads move via GitOps. |
Report a vulnerability
Report vulnerabilities to support@natron.io or through our security.txt. We answer within one business day.
Frequently asked questions
Where is my data?
On Natron Cloud: in a Swiss datacenter on hardware Natron owns, with backups on separate Proxmox Backup Servers. On Flex Stack: in your datacenter. On Azure or Google Cloud: in the region you chose.
Who has access to my VMs and clusters?
Named Natron engineers, through Entra ID single sign-on with least-privilege roles and audit logging. Nobody logs in with shared passwords, and there is no foreign parent company with a legal path to your data.
Are backups encrypted?
VM backups on Proxmox Backup Server are encrypted. Kubernetes backups go to S3-compatible storage with 30 days of retention. We monitor the freshness of every backup job and get an alert when one is missing.
Do you use US cloud services in the data path?
Your workloads and data on Natron Cloud stay on our hardware in Switzerland. For ancillary services such as identity management or website tooling, we send you the list of sub-processors on request.
What happens if the datacenter fails?
Natron Cloud runs in one Swiss datacenter. Power, network and storage are redundant, so a single host, disk or switch failure has no impact. If the whole site is lost, we restore from backups. For higher requirements we build a second site with you, as Flex Stack or as a stretched setup.
How do I get my data back?
You get VMs as qcow2 or raw images, object data over S3 and databases as native dumps; your Kubernetes manifests already live in your Git. We hand over within the notice period of your contract and confirm deletion afterwards.
Do you support audits and questionnaires?
Yes. We answer security questionnaires, provide ISO certificates and a DPA on request, and join audit calls with your auditor.
Questions about security or a DPA?
We answer security questionnaires, provide a data processing agreement on request and support you in audits.