Behind every Denali service is a professionally configured infrastructure, with advanced hardening, active monitoring and full compliance with European and Swiss privacy and data security regulations.
Our servers are not raw virtual machines delivered as-is. Every system is installed, hardened and verified before going into production.
Every server is manually configured by experienced engineers: minimal OS, services reduced to what is necessary, restricted access, centralised logging. No default installation left as-is.
We operate in full compliance with the European GDPR and the Swiss Federal Act on Data Protection (nFADP). Customer data is handled with the utmost confidentiality and is never passed to third parties.
Systems are monitored 24/7 with automatic alerting on anomalies, abnormal resource consumption, intrusion attempts and changes in critical services. Response times are fast.
The technical measures we systematically apply to every production server
Double-layer protection: hardware firewall at network level and software firewall (nftables/iptables) at system level. Only strictly necessary ports are open.
Administrative access is via SSH keys only. Password authentication is disabled. Direct root login is blocked.
Fail2ban and rate limiting systems automatically block IPs attempting brute-force attacks on SSH, control panel, email and web applications.
Every exposed service β web, email, management panel, API β uses up-to-date TLS encryption. Obsolete protocols (SSLv3, TLS 1.0/1.1) are disabled.
Each customer account is isolated at filesystem and process level. A problem on one account cannot spread to others. We use separate processes and restrictive permissions.
OS security patches are applied automatically. Critical packages are updated promptly, without waiting for manual intervention.
All administrative accesses, configuration changes and system events are recorded with timestamps. Logs are stored securely and tamper-proof.
Backups are performed automatically, encrypted before transfer and stored on storage separate from the primary infrastructure. Available for fast restoration when needed.
We do not wait for a problem to occur: we take a proactive approach to security
Anti-DDoS protection is active at datacenter level on all servers. Anomalous traffic is analysed and filtered before reaching the infrastructure, guaranteeing service continuity even under large volumetric attacks.
Intrusion detection systems continuously analyse traffic and process behaviour to identify suspicious patterns, privilege escalation attempts and anomalous access, with immediate notification to the technical team.
All critical services are continuously monitored. Uptime, latency, CPU/RAM/disk usage and daemon status are checked regularly. In case of anomaly, the team is automatically alerted.
In the event of a security incident, our team acts quickly to isolate the problem, restore service and analyse the cause. The customer is transparently informed about what happened and the actions taken.
Operating in compliance with privacy laws is not bureaucracy: it is concrete respect for our customers' data
We process personal data in compliance with Regulation (EU) 2016/679 (GDPR). Customers have the right to access, rectify, delete and port their data. Processing is documented and limited to what is strictly necessary.
Denali PRO SA operates in Switzerland and complies with the new Federal Act on Data Protection (nFADP, in force since 1 September 2023), aligned with European standards and in some respects more restrictive.
Customer data is never sold, shared or passed to third parties for commercial or advertising purposes. Technical sub-processors are carefully selected and bound by confidentiality agreements.
All production infrastructure is located in European datacentres subject to EU regulations. No data is transferred to countries that do not offer an adequate level of protection.
Our privacy policy clearly describes what data we collect, for what purpose and for how long we retain it. No generic disclaimers: only concrete and verifiable information.
All Denali mail servers support STARTTLS and enforced TLS. Communications between servers are encrypted in transit. SPF, DKIM and DMARC are correctly configured on all domains.
The security of your infrastructure is also our responsibility. We do not leave you alone.
We can apply advanced security configuration to your VPS or dedicated server: review of exposed services, firewall configuration, disabling unnecessary access, SSH and web service hardening.
Our team can analyse your environment configuration and suggest the most appropriate security measures. We provide practical guidance, not theoretical reports: every recommendation is designed to be concretely implemented.
If your server or website has been compromised, our team can help with incident analysis, service restoration from backup and identification and resolution of the vulnerability that allowed unauthorised access.
We guide you through the correct SPF, DKIM and DMARC configuration for your domain, improving deliverability and reducing the risk of spoofing and phishing. Available for all SMTP and hosting customers.
For customers with the VPS PRO package we proactively manage security updates, notifying you before each intervention and verifying system stability after application.
In the event of vulnerabilities affecting our systems or your services, we inform you without delay. No concealment, no minimisation: knowing what happened is the first step to resolving and preventing.
Frequently asked questions about Denali infrastructure security
It depends on the plan. Shared hosting plans use physical servers shared among multiple customers, but with strict isolation between accounts at filesystem and process level. VPS plans offer dedicated KVM virtual machines, with guaranteed resources and complete isolation. In both cases the infrastructure is professionally managed by our team.
Yes. Automatic data backups are performed regularly and stored on separate storage. Primary storage uses redundant RAID configurations. In case of hardware failure, restoration takes place quickly thanks to our team's proven procedures.
The production infrastructure is hosted in certified European datacentres (Tier III level or above), with redundant power, multiple connectivity and strict physical access control. Hosting in Switzerland is available on request. Data is never transferred outside the European Union without the customer's explicit consent.
Yes. The hardening service is available as a one-time intervention or included in the VPS PRO package. Contact us to discuss your environment's specific requirements: supported operating systems, installed applications and particular compliance requirements.
We follow major security feeds (CVE, Debian bulletins, vendor advisories) and proactively address critical vulnerabilities, even before official updates are released, through temporary mitigations (firewall rules, disabling vulnerable services, workarounds). Affected customers are always informed.
Yes. We operate in compliance with the GDPR and Swiss nFADP. We can provide upon request a DPA (Data Processing Agreement) for companies that need it for their own compliance. Contact us via ticket or email to receive the documentation.
Need security consulting or want to request hardening for your server?
Contact us