DARCH Get started

Platform and security

How your service is run

Every client sits on the same platform, built once and documented. This page says plainly what it does, how it is protected, and what we do not take on.

The platform in one table

HostingServers in Frankfurt, Germany (EU). Websites sit behind Cloudflare, which absorbs attacks and speeds up delivery.
SeparationEach client runs in its own locked-down container on its own private network, with fixed memory and processor limits. One client cannot see or slow another.
MonitoringWebsites are checked every five minutes, mail services every five to ten minutes, certificates and domain renewal dates every day. A failure sends an alert to a phone, a reminder while it lasts, and a notice when it recovers. Every incident is recorded with its start, its end and what the check reported.
BackupsClient data and mail are backed up every night, encrypted before they are stored. A restore test runs every month and its result is recorded.
EmailOur own mail server with spam filtering, encrypted connections, and SPF, DKIM and DMARC set up for every domain so that others cannot send mail in your name. No adverts, and your mail is never used for advertising or profiling.
AccessAdministration by key only, no shared passwords, a firewall that opens only the ports in use, and automatic security updates. Secrets are stored encrypted.
Change controlThe whole setup is defined in version-controlled files. Every change is rehearsed with a dry run, applied from those files, and recorded, so there is always an answer to "what changed, and when".
DocumentationEvery client setup is written down, with runbooks for common jobs and for recovery, so the service does not depend on one person's memory.

Your data stays yours

Registered in your name

Domains and accounts belong to your organisation. DARCH is the technical contact, never the owner.

A written agreement

Plans come with short written terms, and a data processing agreement wherever we hold personal data for you, such as email.

A way out

If you leave, you get a full copy of your data and written handover notes. Nothing is held back over an unpaid invoice.

Automation and the operations hub

For automation clients we build a hub that the business talks to, instead of everyone talking to the owner.

One source of truth

Rotas, problem reports, tasks and status in one place, so every site and department sees the same picture at the same time.

A private API

Each client gets its own keys with only the access it needs. Your existing tools and the ones we build exchange data through it, and every call is logged.

Alerts and incidents

Rules decide who is told about what. An incident has an owner, a status and a history, visible to the people who need it.

The hub is built per client after a paid discovery, in fixed-price phases. We use proven off-the-shelf tools where they fit.

What we do not take on

Saying no early is part of being safe to hire.

Round-the-clock engineersSupport hours are Monday to Friday, 9:00 to 17:00. Monitoring alerts us at any hour and out-of-hours work is best effort.
Card details and medical recordsWe do not store payment card data or medical records. Payments go through providers built for them.
HardwareNo hardware sales and no on-site repair.
TrackingNo tracking-heavy marketing, and nothing we could not explain to the people it affects.
Testing without permissionWe never scan or test anyone's systems without written permission. The free health check uses public information only.

Questions about how your data would be handled?

Ask us. You get a plain answer in writing.

Get in touch