Company / Security
Security and datacenter
Data sovereignty comes down to a few concrete questions: where the data is stored, who can reach it and what the operation depends on. This page answers them.
The datacenter and network sections describe Natron Cloud. On Natron Flex Stack the platform sits in your datacenter and we run it the same way. On Bring Your Own Cloud (Azure, Google Cloud, on-premise) the datacenter belongs to the provider or to you. The platform, access, backup and operations sections apply unchanged, because the same base runs on our AKS and GKE clusters.
The datacenter
Switzerland, own hardware
Natron Cloud runs on servers Natron owns, in a Tier 4 certified Swiss datacenter. No hosting provider sits between you and us.
Redundant power and network
Power feeds, uplinks and switches are redundant. A single component can fail without impact on your workloads.
Network
Default deny between zones
Management, services, customers and the internet are separate zones, and traffic between them is denied unless a rule allows it. Customers never reach each other.
An isolated network per customer
Every customer gets an own network segment behind the firewall.
Platform
Proxmox VE with Ceph
Storage is replicated three ways, HA follows affinity rules, and VMs are live-migrated for maintenance.
Kubernetes hardening
We run upstream Kubernetes with etcd encryption at rest, API audit logging, single sign-on with role-based access and restricted pod security standards.
Encrypted in transit
Traffic between cluster nodes is encrypted, and network policies deny by default.
Runtime and supply chain
Runtime security (Falco), policy enforcement (Kyverno), image scanning, software bills of materials and VM-isolated pods (Kata Containers) are available as managed services on top of any cluster. We support SLSA provenance for your build pipelines and help you introduce it.
Who has access
Named engineers in Switzerland
Only Natron engineers operate the platform. Every login is personal, through single sign-on, with least-privilege roles and audit logging.
No shared passwords, no secrets in code
Access uses personal identities and keys. Secrets are stored encrypted in a secrets manager, and the CI blocks commits that contain them.
Backup and recovery
VMs every night
Every VM is backed up nightly to separate backup servers at a second Swiss location, and we monitor that every job ran. Immutable (WORM) storage is available as an option.
Kubernetes every night
Clusters are backed up nightly with 30 days of retention.
Restore is part of operations
The same team runs restores as ordinary operations tasks, following a documented runbook.
Operations
Everything as code
The infrastructure is defined as code. Every change is reviewed and validated in CI before it reaches production.
Monthly staged patching
Patches go to dev first, then staging, then production. Versions are pinned, and updates need a review before they ship.
Monitoring and on-call
Metrics and logs are retained, alerts reach the on-call engineer around the clock by severity, and a dead-man's switch pages if monitoring itself goes quiet.
Compliance
ISO 27001 and ISO 9001
Natron Tech AG is certified for information security and quality management. Certificates are available on request.
nDSG and GDPR
Data processing under Swiss law. A data processing agreement (AVV/DPA) and the list of sub-processors are available on request.
Swiss company, no foreign parent
Natron Tech AG is owned by its founders and board in Bern. No parent company outside Switzerland can be compelled to hand over your data.
Exit and data return
Open formats
We export VMs as qcow2 or raw images, object data over S3, databases as native dumps; Kubernetes manifests live in your own Git repository.
No technical lock-in
The whole stack is open source: Proxmox, Ceph, upstream Kubernetes, Cilium. What runs here also runs elsewhere.
Sovereignty in four layers
The word means little on its own. Four questions per target make it concrete.
| Layer | Natron Cloud | Natron Flex Stack | Bring Your Own Cloud |
|---|---|---|---|
Ownership Who owns the hardware and the company? | Natron Tech AG, Bern. No foreign parent. | You own the hardware; Natron operates it. | The cloud provider or you; Natron operates the platform. |
Residency Where do data and backups live? | Switzerland, two locations: production in one datacenter, backups at a second site. | Your datacenter. | The region you choose at the provider, or your datacenter. |
Operational access Who can log in? | Named Natron engineers via SSO, least privilege, audited. | The same, plus your own staff if you want. | Natron engineers via SSO; the provider retains its own platform access. |
Technical dependencies What would we need to replace to leave? | Nothing proprietary: Proxmox, Ceph, upstream Kubernetes. | The same. | The provider's managed Kubernetes and storage; workloads move via GitOps. |
Report a vulnerability
Report vulnerabilities by mail or through our security.txt. We answer within one business day.
Frequently asked questions
Where is my data?
On Natron Cloud: in a Swiss datacenter on hardware Natron owns, with backups at a second Swiss location. On Flex Stack: in your datacenter. On Azure or Google Cloud: in the region you chose.
Who has access to my VMs and clusters?
Named Natron engineers, through single sign-on with least-privilege roles and audit logging. Nobody logs in with shared passwords, and there is no foreign parent company with a legal path to your data.
How do backups work?
Backups live at a second Swiss location, Kubernetes backups keep 30 days of retention, and we monitor every backup job and get an alert when one is missing. Immutable (WORM) storage is available as an option; tell us what your policy requires and we set it up.
Do you use US cloud services in the data path?
Your workloads and data on Natron Cloud stay on our hardware in Switzerland. For ancillary services such as identity management or website tooling, we send you the list of sub-processors on request.
What happens if the datacenter fails?
Natron Cloud runs in one Swiss datacenter. Power, network and storage are redundant, so a single host, disk or switch failure has no impact. If the whole site is lost, we restore from the backups at the second location. For higher requirements we build a second site with you, as Flex Stack or as a stretched setup.
How do I get my data back?
You get VMs as qcow2 or raw images, object data over S3 and databases as native dumps; your Kubernetes manifests already live in your Git. We hand over within the notice period of your contract and confirm deletion afterwards.
Do you support audits and questionnaires?
Yes. We answer security questionnaires, provide ISO certificates and a DPA on request, and join audit calls with your auditor.
Questions about security or a DPA?
We answer security questionnaires, provide a data processing agreement on request and support you in audits.