Announcements | Substack | Knowledge Base | Hosting Panel

Infrastructure security and protection

Behind every Denali service is a professionally configured infrastructure, with advanced hardening, active monitoring and full compliance with European and Swiss privacy and data security regulations.

Not just VPS: professional infrastructure

Our servers are not raw virtual machines delivered as-is. Every system is installed, hardened and verified before going into production.

πŸ”§

Professional configuration

Every server is manually configured by experienced engineers: minimal OS, services reduced to what is necessary, restricted access, centralised logging. No default installation left as-is.

πŸ‡ͺπŸ‡Ί

EU and Swiss compliance

We operate in full compliance with the European GDPR and the Swiss Federal Act on Data Protection (nFADP). Customer data is handled with the utmost confidentiality and is never passed to third parties.

πŸ“‘

Continuous monitoring

Systems are monitored 24/7 with automatic alerting on anomalies, abnormal resource consumption, intrusion attempts and changes in critical services. Response times are fast.

Infrastructure hardening

The technical measures we systematically apply to every production server

πŸ›‘οΈ

Multi-level firewall

Double-layer protection: hardware firewall at network level and software firewall (nftables/iptables) at system level. Only strictly necessary ports are open.

πŸ”

SSH access with cryptographic keys

Administrative access is via SSH keys only. Password authentication is disabled. Direct root login is blocked.

🚫

Automatic attack blocking

Fail2ban and rate limiting systems automatically block IPs attempting brute-force attacks on SSH, control panel, email and web applications.

πŸ”’

TLS on all services

Every exposed service β€” web, email, management panel, API β€” uses up-to-date TLS encryption. Obsolete protocols (SSLv3, TLS 1.0/1.1) are disabled.

πŸ“¦

Account isolation

Each customer account is isolated at filesystem and process level. A problem on one account cannot spread to others. We use separate processes and restrictive permissions.

πŸ”„

Automatic security updates

OS security patches are applied automatically. Critical packages are updated promptly, without waiting for manual intervention.

πŸ“‹

Logging and audit trail

All administrative accesses, configuration changes and system events are recorded with timestamps. Logs are stored securely and tamper-proof.

πŸ’Ύ

Encrypted off-site backup

Backups are performed automatically, encrypted before transfer and stored on storage separate from the primary infrastructure. Available for fast restoration when needed.

Active protection against threats

We do not wait for a problem to occur: we take a proactive approach to security

🌊

Anti-DDoS protection

Anti-DDoS protection is active at datacenter level on all servers. Anomalous traffic is analysed and filtered before reaching the infrastructure, guaranteeing service continuity even under large volumetric attacks.

πŸ”

Intrusion detection (IDS)

Intrusion detection systems continuously analyse traffic and process behaviour to identify suspicious patterns, privilege escalation attempts and anomalous access, with immediate notification to the technical team.

πŸ“Š

24/7 monitoring

All critical services are continuously monitored. Uptime, latency, CPU/RAM/disk usage and daemon status are checked regularly. In case of anomaly, the team is automatically alerted.

⚑

Fast incident response

In the event of a security incident, our team acts quickly to isolate the problem, restore service and analyse the cause. The customer is transparently informed about what happened and the actions taken.

πŸ›‘οΈ Security is not an add-on: it is included by default in all Denali plans, from shared hosting to dedicated servers.

European and Swiss regulatory compliance

Operating in compliance with privacy laws is not bureaucracy: it is concrete respect for our customers' data

πŸ‡ͺπŸ‡Ί

GDPR β€” European regulation

We process personal data in compliance with Regulation (EU) 2016/679 (GDPR). Customers have the right to access, rectify, delete and port their data. Processing is documented and limited to what is strictly necessary.

πŸ‡¨πŸ‡­

nFADP β€” Swiss data protection law

Denali PRO SA operates in Switzerland and complies with the new Federal Act on Data Protection (nFADP, in force since 1 September 2023), aligned with European standards and in some respects more restrictive.

🚫

No data transfer to third parties

Customer data is never sold, shared or passed to third parties for commercial or advertising purposes. Technical sub-processors are carefully selected and bound by confidentiality agreements.

πŸ“

Data hosted in Europe

All production infrastructure is located in European datacentres subject to EU regulations. No data is transferred to countries that do not offer an adequate level of protection.

πŸ“„

Transparent privacy policy

Our privacy policy clearly describes what data we collect, for what purpose and for how long we retain it. No generic disclaimers: only concrete and verifiable information.

βœ‰οΈ

Encrypted and secure email

All Denali mail servers support STARTTLS and enforced TLS. Communications between servers are encrypted in transit. SPF, DKIM and DMARC are correctly configured on all domains.

Security assistance for customers

The security of your infrastructure is also our responsibility. We do not leave you alone.

πŸ”§

Server hardening on request

We can apply advanced security configuration to your VPS or dedicated server: review of exposed services, firewall configuration, disabling unnecessary access, SSH and web service hardening.

πŸ”Ž

Review and consulting

Our team can analyse your environment configuration and suggest the most appropriate security measures. We provide practical guidance, not theoretical reports: every recommendation is designed to be concretely implemented.

πŸ†˜

Support in case of incident

If your server or website has been compromised, our team can help with incident analysis, service restoration from backup and identification and resolution of the vulnerability that allowed unauthorised access.

πŸ“¬

Secure email and SMTP assistance

We guide you through the correct SPF, DKIM and DMARC configuration for your domain, improving deliverability and reducing the risk of spoofing and phishing. Available for all SMTP and hosting customers.

πŸ”„

Guided updates

For customers with the VPS PRO package we proactively manage security updates, notifying you before each intervention and verifying system stability after application.

πŸ’¬

Direct and transparent communication

In the event of vulnerabilities affecting our systems or your services, we inform you without delay. No concealment, no minimisation: knowing what happened is the first step to resolving and preventing.


FAQ

Frequently asked questions about Denali infrastructure security

It depends on the plan. Shared hosting plans use physical servers shared among multiple customers, but with strict isolation between accounts at filesystem and process level. VPS plans offer dedicated KVM virtual machines, with guaranteed resources and complete isolation. In both cases the infrastructure is professionally managed by our team.

Yes. Automatic data backups are performed regularly and stored on separate storage. Primary storage uses redundant RAID configurations. In case of hardware failure, restoration takes place quickly thanks to our team's proven procedures.

The production infrastructure is hosted in certified European datacentres (Tier III level or above), with redundant power, multiple connectivity and strict physical access control. Hosting in Switzerland is available on request. Data is never transferred outside the European Union without the customer's explicit consent.

Yes. The hardening service is available as a one-time intervention or included in the VPS PRO package. Contact us to discuss your environment's specific requirements: supported operating systems, installed applications and particular compliance requirements.

We follow major security feeds (CVE, Debian bulletins, vendor advisories) and proactively address critical vulnerabilities, even before official updates are released, through temporary mitigations (firewall rules, disabling vulnerable services, workarounds). Affected customers are always informed.

Yes. We operate in compliance with the GDPR and Swiss nFADP. We can provide upon request a DPA (Data Processing Agreement) for companies that need it for their own compliance. Contact us via ticket or email to receive the documentation.

Need security consulting or want to request hardening for your server?

Contact us