IT departments, tenders, risk assessments

When the application cannot stop

Choosing a hosting provider for a critical application is not buying machines: it is entrusting someone with the fact that they keep running, that they are backed up, and that a person answers when they stop. This page sets out what D&D actually does — and what belongs in a contract rather than on a website.

Day-to-day operations

What is in place for every machine we host, with no surcharge and no option to tick.

Daily backup

Virtual machines are backed up every day on D&D’s Swiss infrastructure. Restoration is part of the service.

Infrastructure monitoring

The infrastructure is monitored automatically and alerts are handled by D&D’s technical team. It happens that we already know when you call.

Operating system maintained

Installation, updates and upkeep of the system are D&D’s responsibility. The application stays with you, unless agreed otherwise.

Hardware redundancy

If a virtualisation host fails, the machine can restart on another host in the infrastructure.

Separate environments

Production, staging and test where they are needed — so that nobody has to test in production.

A technical point of contact

The person who answers operates the infrastructure: they can read the logs, look at the state of the machine and act.

What happens when something breaks

The sequence, without a committed response time — that is agreed contractually, according to how critical your services are.

Detection

Either monitoring raises an alert, or you report the problem. Both routes reach the same people.

Ownership

The request is not triaged by a front desk: it reaches someone with access to your machine who knows your configuration.

Diagnosis

Logs, host state, storage, network. We tell you what we see — including when the cause is in the application and therefore on your side.

Recovery

Restart, failover to another host, restoration from backup: which one depends on the failure and on what was planned with you.

Report

What happened, what was done, and what would stop it happening again.

What is standard, and what is contractual

This is the distinction a risk assessment is looking for, and it is more useful than a generic table of service levels.

Included by default

  • Daily backup on the Swiss infrastructure
  • Restoration on your request
  • Infrastructure monitoring and handling of alerts
  • Upkeep and updates of the operating system
  • Test and staging environments where they are needed
  • A named technical point of contact

Agreed with you, in the contract

  • Response and recovery times
  • Intervention outside business hours
  • Backup retention period
  • Replication to a second Swiss data centre
  • Tolerated data loss and outage duration objectives
  • High-availability architecture, designed for your application
  • Data processing agreement describing the hosting chain

We do not publish a ready-made table of service levels. A recovery commitment only means something in relation to a specific application, a specific architecture and a specific budget — and a figure printed on a website binds nobody. The ones that apply to you are in your contract.

You must be able to leave

Few hosting providers address this on their website, and it is often what decides a tender.

An infrastructure you cannot get out of is a risk, however good the provider. A company entrusting a critical application should know, before signing, how it would leave — in the event of a disagreement, a change of strategy, or simply because we stopped being the right fit.

D&D’s answer rests first on a technical choice: there is nothing proprietary to convert. We host virtual machines running common operating systems, PostgreSQL or MariaDB/MySQL databases, and files on an ordinary filesystem. No in-house layer sits between your application and you.

In practice, a handover to another provider requires no format translation: what runs here runs elsewhere. That is the opposite of a platform whose managed services exist nowhere else.

  • Your data is yours. We host it; we do not exploit it and we derive nothing from it.
  • Your domain names are registered in your name. You remain the registrant, even when an integrator requested them on your behalf.
  • Standard formats. Machine images, backups, database exports: nothing that only exists here.
  • An exit is prepared. The technical material needed for a handover, and coordination with the incoming provider, are agreed like everything else — beforehand, not during.

What this site will not tell you

You will find no availability percentage here, no recovery time, no retention period. That is not an oversight.

Those values only mean something in relation to an architecture and a contract. Printed on a home page they cost nothing to write and bind nobody — which is precisely why they are so common.

If your file needs figures, they will come from a conversation with the technical team and will appear in the contract, where they carry weight. We answer auditors’ and procurement teams’ questions in writing.

What your risk assessment can establish

The factual elements we document, which usually carry more weight than a compliance badge.

Where the data is

Machines, storage, backups and any replication, all hosted in Switzerland. The detail, including the caveats.

Who can access it

The D&D team, from Switzerland. No external administrative access to the hypervisors.

Who operates it

D&D, on hardware it owns. No hyperscaler in the hosting chain.

Which subcontractors

The list is short and we give it, including the spam filtering service that may sit outside Switzerland.

Where the building is

The Crissier data centre, operated by BrainServe, with a clear separation between what belongs to the building and what belongs to D&D.

How to get out

Standard formats, no proprietary dependency. Reversibility is a property of the technical set-up, not a sales promise.

Tender questions

Do you offer an SLA?

Service commitments are defined contractually, according to how critical your application is and the architecture chosen. We do not publish a generic table.

This is deliberate: a recovery commitment depends on what has to be recovered. The same figure has neither the same cost nor the same meaning for a brochure site and for an ERP the invoicing depends on.

Is the infrastructure monitored continuously?

The infrastructure is monitored automatically and alerts are handled by D&D’s technical team.

Arrangements for intervention outside business hours are agreed contractually. We would rather discuss it before the incident than during it.

What happens if a data centre becomes unavailable?

Replication to another infrastructure or data centre located in Switzerland can be put in place where requirements justify it.

It does not replace backup: whatever is written on one site is copied to the other, errors included. The two mechanisms answer different risks, and the page devoted to them explains this in detail.

Can we have a test environment?

Yes. Staging and test environments are common, particularly for acceptance testing and version migrations. They are created where they are needed.

How do we get our data back if we leave?

There is nothing to convert: virtual machines, common operating systems, PostgreSQL or MariaDB/MySQL databases. What runs here runs elsewhere.

The technical material needed for a handover and coordination with the incoming provider are agreed contractually, like everything else.

Will you complete a security questionnaire?

Yes. Location, operations, access, subcontractors, data centre characteristics: we answer in writing and provide what your procurement team or auditor needs.

A file to put together?

Describe the application, the availability you need and your constraints. We answer precisely — including when the answer is that we are not the right provider.