noalen.ai

All services · 06

Managed Hosting

Your application runs. Security, backups, monitoring and response are our responsibility — operated in Germany.

A server is rented quickly. What comes after is the work: security updates nobody installs, backups nobody ever restored, certificates that expire on a Sunday. Managed hosting at noalen means: you hand over the application and get operations back — complete, with a name and a response time. None of it is yours to assemble or keep an eye on.

At noalen, websites, applications and servers run on our own hardware in Germany — in a data centre, not in someone else's cloud under someone else's law. Patching, backup, monitoring and access logs are included; your data stays in Germany, and you always know where.

The difference is not the server — you can rent one anywhere. The difference is what runs on it: a security stack of update management, vulnerability scans, attack detection (SIEM) and role-based access, and an operations stack of monitoring and alerting, backups with restore drills and operations by ITIL processes. Both are always included at noalen, never an add-on. So you get what large companies expect from their operations — fixed processes, commitments, responsibility — combined with the DevOps principles that keep operations affordable: automation, short paths, every change checked and reversible.

What you get: operations as a whole, with responsibility

Managed servers in Germany
Dedicated or virtual servers on our own hardware, encrypted connections, server location Germany. No third country, no subcontractor outside the EU.
Update management and vulnerability scans
Security updates for operating system, services and dependencies in fixed maintenance windows, critical gaps out of turn. Daily vulnerability scans of all running images with deadlines by severity; hardening to the state of the art. Only what is checked and signed goes live.
Attack detection (SIEM)
Central analysis of logs from servers, services and access points, rules for attack patterns, automatic blocking of attacks from the network, runtime detection on the servers. Incidents are detected, logged and followed up.
Role-based access (RBAC)
Who may do what is defined in roles, not in people's heads: access only with a personal key and a log, rights by task, secrets in a vault instead of files, revocation with one action.
Monitoring and alerting
Availability, load and error rates measured around the clock; alerts with thresholds, escalation and an alert chain down to the phone — before the customer calls, not after. Optionally on-call with an agreed response time.
Backups that get restored
Daily backups with retention at a second location — and regular restore drills. A backup that has never been tested is a hope.
Operations by ITIL processes
Incidents, changes and root causes (problem management) follow fixed procedures: maintenance windows announced in advance, every change with a documented rollback, runbooks for the standard cases, reports on request.
For websites, applications or your existing software
We operate what we built — and just as well what you bring along: your line-of-business application, your shop, your database. Migration included.
Honest commitments
Target availability, response times and maintenance windows are in the contract. A GDPR data processing agreement is part of it. What we cannot guarantee, we do not promise.

The drawing explained

Every box in the architecture drawing stands for a service that is part of managed hosting — from your users' access to on-call. What the individual components mean:

The users' path

Your users
Customers, staff, partners — everyone who opens your application in a browser or via an API. Their path always leads through the access layer, never directly to a server.
Access
The front door of the data centre: every connection is TLS-encrypted, certificates renew automatically. Suspicious requests — password guessing, scans, known attack patterns — are detected and their senders blocked before they reach an application.

Inside the data centre

Data centre
Our own hardware in a data centre in Germany — no hyperscaler, no subcontractor outside the EU. You always know where your data is and under which law.
Your applications
Websites, business applications, APIs — each runs isolated from the others in its own environment with defined resources. A problem in one application stays in that application.
Databases
Managed databases with daily backups, encrypted connections and access only from the network of their own application. Updates and maintenance are included.
Role-based access (RBAC)
Who may do what is defined in roles, not in people's heads: every access with a personal key and a log, rights by task, revocation in one step — for ourselves as well.
Secrets in a vault
Passwords, keys and credentials live in an encrypted vault, not in files or configuration. Applications receive their secrets at runtime; every access is logged.

Security stack — five layers

Update management & patching
Security updates for operating system, services and dependencies in fixed maintenance windows, critical vulnerabilities out of turn. Every state is documented and reversible.
Vulnerability scans
All running images are checked daily against the current vulnerability databases, with deadlines by severity. Only what has been checked and signed goes live.
Attack detection (SIEM)
Logs from servers, services and access points are collected centrally and evaluated against rules for attack patterns. Hits are reported, logged and followed up.
Runtime detection
What applications do in operation is observed on the server itself: unusual processes, file access or network connections trigger an alert — even when the attack does not come from outside.
Roles & rights (RBAC)
The same role rule applies to operations itself: administration only with a personal key, rights by task, every change traceable.

Operations stack

Monitoring & alerting
Availability, response times, load and error rates are measured around the clock — per application and for the platform. Thresholds trigger alerts before users notice anything.
Alert chain
An alert has a fixed path: notification, escalation by time, handover to a person. No alert gets lost in a mailbox.
On-call
At the end of the chain is a person with a phone and an agreed response time — around the clock if you wish, otherwise within the agreed hours.
Daily backup
Applications and databases are backed up daily, encrypted, with a fixed retention period. The backup runs without anyone's intervention — and is monitored like any other service.
Restore drill
A backup that has never been restored is a hope. That is why we regularly rehearse whether a working state can actually be rebuilt from the backup — with measured duration.
Second location
A copy of the backup is stored at a second, separate location. If the data centre fails, the data is still there.
Operations by ITIL
Incidents, changes and recurring causes (problems) run as fixed processes with a ticket, an owner and evidence — not by shouting across the room.

Three situations

What managed hosting means day to day.

The manufacturer with the server in the storeroom

A manufacturing company's inventory system runs on a server in the back room. The colleague who knew it has retired. Nobody knows whether the backup works.

Move to a managed server in Germany with patching, daily backups and restore drills. An operations concept as a document, a contact person with a name. The storeroom is a storeroom again.

The agency that no longer wants to host

An advertising agency runs twenty websites for its clients on a rented server — and is responsible for incidents at night without ever having wanted to be.

The client sites run with us: monitoring, updates, certificates, on-call. The agency designs, we operate — with one invoice per client if desired.

The company with the data protection question

A service provider processes customer data in an application at a US cloud provider. Its largest customer asks about the server location in a tender.

Move of the application to our own hardware in Germany, data processing agreement, documented data flow. The answer in the tender is one sentence with evidence.

Maintenance, further development and support for your application: SaaS solutions

Still undecided? The guide compares managed hosting, cloud and your own server — cost, data protection, responsibility: Having your application operated

How it works

  1. Intake

    What runs where today, which data, which dependencies, which commitments do you need? From that comes the operations concept.

  2. Migration

    Setup, migration, test run together with you. Switch-over only when both sides are green — the old environment stays up until then.

  3. Ongoing operation

    Maintenance windows at night on weekdays, reports on request, service period on every invoice. Term and notice as individually agreed — you get your data back in full in any case.

Does this fit your task?

Write to me about what it is — I answer personally and tell you honestly whether and how it fits.

Get in touch