ALPINELAYER · Swiss Cloud InfrastructureSales: sales@alpinelayer.ch · Support: support@alpinelayer.ch
All ProductsSolutionsPricingInfrastructureDevelopersCompanyContact
Legal & Policies

Security Policy

High-level security practices for AlpineLayer infrastructure and operations.

Version 1.0Last updated 2 September 2026English

1. Security program

The security program is designed around least privilege, strong authentication, network controls, logging, vulnerability management, change management, backup, incident response and supplier risk management.

2. Access

Administrative access should be role-based, reviewed periodically, protected with MFA and revoked promptly when no longer needed.

3. Logging and monitoring

Security-relevant authentication, administration and infrastructure events should be logged and monitored with access limited to authorized personnel.

4. Vulnerability management

AlpineLayer should maintain processes for vulnerability intake, severity assessment, patching and emergency remediation. Managed customer systems are patched according to purchased scope.

5. Incident response

Confirmed incidents are handled through triage, containment, eradication, recovery, evidence preservation, notification and post-incident review appropriate to severity.

6. Customer responsibility

Customers remain responsible for code, passwords, users, content, plugins and configurations outside the purchased managed scope.

7. Certifications

AlpineLayer must not claim ISO, SOC or other certification until actually obtained. Roadmap certifications must remain clearly labeled as future.