Secure

IT infrastructure
available in full at

under your control

Infrastructure and Hosting

We operate dedicated systems on our own hardware in Switzerland – stable, traceable and designed to meet regulatory requirements – audit-ready and compliant with audit standards. Without any reliance on international cloud providers.

Infrastructure,

– it’s just right

Setting up a regulatory-compliant IT environment – for example, in line with standards such as ISO 27001 – is a complex process that ties up internal resources. At the same time, it creates dependencies that pose risks, particularly in regulated sectors.

Our infrastructure is designed to meet these requirements right from the start. It is fully documented, audit-ready and ready for immediate use. This eliminates the usual set-up effort – and frees up time for you to focus on your core business.

Products

We are happy to offer you our services in the form of ready-made products. However, bespoke combinations are also possible.

Core Infrastructure & Operations

Secure infrastructure.

Full data sovereignty.

A highly available IT infrastructure, operated entirely in Switzerland, providing a secure foundation for all services – isolated, auditable and with full data sovereignty.
Mehr erfahren

Core Infrastructure & Operations

SIS – SicherInfrastrukturSchweiz is a high-availability IT infrastructure operated in Switzerland, serving as the foundation for all our other services: running on our own hardware, fully isolated, documented and auditable.

Features

  • Dedicated servers (physical or virtualised)
  • Network segmentation (VLANs, firewalls, zero-trust approaches)
  • Redundant storage systems
  • Backup and recovery strategies (including off-site backup in Switzerland)
  • Monitoring, patch and lifecycle management

Scope of services

  • Provision of dedicated servers (physical / virtualised) in Switzerland
  • Redundant storage and network infrastructure
  • Network segmentation (VLAN, firewall, DMZ)
  • System monitoring (24/7) including alerts
  • Regular security and operating system updates
  • Backup and restore strategy (including off-site backup in Switzerland)

Your benefits

  • Full data sovereignty and auditability without access by third countries
  • Support for GxP, ISO 27001, NIS2, DSG, GDPR
  • Clear responsibilities (no shared responsibility risk)
  • Audits and inspections without third-country risks
  • Reduction of operational IT risks

Particularly suitable for

  • All regulated environments
  • Systems subject to validation
  • Critical business applications

User, Role & Access Control

Clear permissions.

Traceable access.

Secure and transparent management of users, roles and access rights across all systems – including MFA, SSO and auditable logging.
Mehr erfahren

User, Role & Access Control

Centralised management of users, roles and access rights across all systems: traceable, documented and secure.

Features

  • Centralised Identity Management (LDAP / IAM)
  • Role and Permission Models
  • Multi-factor authentication (MFA)
  • Single Sign-On (SSO)
  • User lifecycle (Joiner/Mover/Leaver)
  • Logging of all accesses and changes

Your benefits

  • Minimisation of security and insider risks
  • Clear responsibilities and audit trails
  • Support for segregation of duties
  • Audit-ready user management
  • Compliance with security and regulatory guidelines

Particularly suitable for

  • Regulated user access
  • Organisations with clear role models
  • Security-critical environments

IT Security & Compliance Policies

Consistent security.

Integrated compliance.

Ganzheitliches Sicherheits- und Compliance-Framework mit technischen Schutzmassnahmen, zentralem Monitoring und auditierbarer Umgebung für regulierte Umgebungen.
Mehr erfahren

IT Security & Compliance Policies

Comprehensive security and policy framework.

Functionalities

  • Definition and technical implementation of security policies
  • System hardening & baseline configurations
  • Device management, including Mobile Device Management (MDM)
  • Firewall & network rules
  • Local, self-managed password manager
  • Email certificates, MPKI
  • Centralised spam and virus protection
  • Endpoint monitoring
  • Centralised logging & log management
  • Vulnerability management
  • Incident response processes

Your benefits

  • Verifiable implementation of security requirements
  • Support for ISO 27001, GxP, BSI, NIST
  • Reduction of cyber and compliance risks
  • Clear documentation for audits and inspections

Particularly suitable for

  • ISO 27001 / GxP / DSG / NIS2
  • Pharmaceuticals & medical technology
  • Public administration

Customised servers & specialised environments

Maximum insulation.

Total control.

Dedicated servers and isolated environments for critical applications, systems requiring validation and sensitive data – secure, traceable and auditable.
Mehr erfahren

Customised servers & specialised environments

Dedicated servers or isolated environments for data requiring special protection or systems subject to validation.

Features

  • Dedicated hardware (optional)
  • Physical or logical client separation
  • Validation support (IQ/OQ/PQ)
  • Custom configurations & legacy systems
  • Customised SLA models

Your benefits

  • Maximum isolation & control
  • Simplified validation and auditing
  • Ideal for validation, critical applications and sensitive data
  • No resource sharing
  • Simplified regulatory and customer audits
  • High level of planning and operational reliability

Particularly suitable for

  • Critical systems
  • Applications requiring validation
  • Highly sensitive data
  • Secure infrastructure.

    Full data sovereignty.

    Core Infrastructure & Operations

    A highly available IT infrastructure, operated entirely in Switzerland, providing a secure foundation for all services – isolated, auditable and with full data sovereignty.
  • Clear permissions.

    Traceable access.

    User, Role & Access Control

    Secure and transparent management of users, roles and access rights across all systems – including MFA, SSO and auditable logging.
  • Consistent security.

    Integrated compliance.

    IT Security & Compliance Policies

    Ganzheitliches Sicherheits- und Compliance-Framework mit technischen Schutzmassnahmen, zentralem Monitoring und auditierbarer Umgebung für regulierte Umgebungen.
  • Maximum insulation.

    Total control.

    Customised servers & specialised environments

    Dedicated servers and isolated environments for critical applications, systems requiring validation and sensitive data – secure, traceable and auditable.

We offer you

  • Swiss data sovereignty

    All systems are operated exclusively in Switzerland – on dedicated servers in a controlled environment. Data does not leave the country, and access from third countries is prevented. This ensures that you retain full control at all times – legally, technically and organisationally.
  • For demanding environments

    The solution is designed for organisations where availability, security and traceability are not optional. It provides a robust foundation in situations where systems need to be validated (e.g. as part of GxP or IQ/OQ/PQ validations) or where regulatory requirements shape operations.
  • Can be expanded if required

    The infrastructure can be expanded in a targeted manner to meet specific requirements – for example, through isolated environments, dedicated hardware or support with validation and audit preparations. This ensures the system remains flexible without compromising on clarity and control.
  • International standards

    The entire environment is based on established standards and regulatory requirements such as ISO 27001, ISO 13485 and other industry-specific requirements.
  • Expertise and resources

    In addition to the technical solution, Compliag AG also provides qualified specialists. Whether for audits, regulatory matters or operational support – expertise can be brought in flexibly, without the need to build up internal resources over the long term or delay projects.
  • Swiss data sovereignty
    All systems are operated exclusively in Switzerland – on dedicated servers in a controlled environment. Data does not leave the country, and access from third countries is prevented. This ensures that you retain full control at all times – legally, technically and organisationally.
  • For demanding environments
    The solution is designed for organisations where availability, security and traceability are not optional. It provides a robust foundation in situations where systems need to be validated (e.g. as part of GxP or IQ/OQ/PQ validations) or where regulatory requirements shape operations.
  • Can be expanded if required
    The infrastructure can be expanded in a targeted manner to meet specific requirements – for example, through isolated environments, dedicated hardware or support with validation and audit preparations. This ensures the system remains flexible without compromising on clarity and control.
  • International standards
    The entire environment is based on established standards and regulatory requirements such as ISO 27001, ISO 13485 and other industry-specific requirements.
  • Expertise and resources
    In addition to the technical solution, Compliag AG also provides qualified specialists. Whether for audits, regulatory matters or operational support – expertise can be brought in flexibly, without the need to build up internal resources over the long term or delay projects.

Start a project

Are you redesigning your infrastructure or looking to optimise your hosting? We can help you build stable, secure and future-proof solutions.

Request a consultation

Please get in touch – we’ll be in touch with you within two working days.