Staex Hosting

Managed hosting · Switzerland

Your company's data, on machines you can point at.

Most "European" hosting is a European billing address in front of American infrastructure. Staex Hosting runs on named machines in Switzerland, under Swiss jurisdiction, operated by a person you can call.

46.2044° N, 6.1432° E · Geneva
Swiss jurisdiction · revised FADP + GDPR
No US CLOUD Act exposure
Your own virtual machine · not a shared container
CHF 0.00 egress fees

Private beta — not yet accepting customers. The platform runs, tenant isolation is tested, and the compliance work is built in rather than bolted on. What is not finished is production network transit, offsite backups, and the legal wrapper. Those are listed in full under Limits, because you should not have to find them out later.

Why it matters for a Swiss company

Three things a hyperscaler cannot give you

01 — Jurisdiction

One legal system, not two

A US-owned provider is reachable under the CLOUD Act wherever the servers physically sit. Staex Hosting is Swiss-operated on Swiss hardware, so your data answers to Swiss law and the revised FADP — not to two systems at once.

02 — Cost

Egress is free, and stays free

Hyperscalers price bandwidth out of your data centre as a penalty for leaving. There is no egress charge here, which also means no financial reason you cannot take your data and go.

03 — Support

A named operator, not a ticket queue

Small infrastructure has one honest advantage: when something breaks, you reach the person who built it, in your timezone, in your language. That does not scale — which is exactly why it is worth something.

The actual hardware

We publish the machines. Ask anyone else for theirs.

Data sovereignty is a claim about physical objects. Here are the physical objects.

NodeRoleCPUMemoryStorage
ROG Strix Tenant compute Ryzen 9 7945HX · 32 threads 30 GB 873 GB NVMe · 2.8 GB/s
Blade Stealth Public edge · tenant compute Core i7-8565U · 8 threads 15 GB 238 GB NVMe
mac-node Control plane · database Apple M1 · 8 cores 16 GB unified 179 GB NVMe · 3.9 GB/s

All three sit in Geneva on one private network. Nothing crosses a border to reach another node. Customer machines run on the ROG and the Blade; mac-node holds the accounts and never runs tenant workloads, so the record of who owns what is not on the same machine as the workloads.

Plans

Buy a ceiling, not a reservation

S1

CHF 4/mo

vCPU
1
RAM
1 GiB
Disk
10 GiB

S2

CHF 8/mo

vCPU
2
RAM
2 GiB
Disk
20 GiB

S4

CHF 16/mo

vCPU
4
RAM
4 GiB
Disk
40 GiB

S8

CHF 32/mo

vCPU
8
RAM
8 GiB
Disk
80 GiB

What the numbers actually mean

Your vCPU figure is a ceiling you can always reach, not a slice held in reserve. When your neighbours are idle you get their unused cycles; when they wake up you drop back to your share, within milliseconds, because the scheduler does this in the kernel rather than in a billing system. You are never throttled below what you bought.

You are not limited to these four shapes. Processor, memory and storage are priced separately — CHF 1.20 per vCPU, CHF 2.20 per GB of memory, CHF 0.06 per GB of storage — so you can size each one for what you actually need. Memory costs more per unit because memory is the scarcest thing in the racks; a machine that wants cores and disk but little RAM is genuinely cheaper here.

Every server includes 50 Mbit/s in and out, with no charge for the traffic itself and no cap on how much of it you use.

Size a server and see the price

How your data is handled

Built in at the start, because it cannot be added later

KVM

A real machine, not a shared kernel

Most cheap hosting puts customers in containers, which share the host's operating system kernel: one flaw in it reaches everyone. You get a full virtual machine with its own kernel, so separating you from your neighbours is the processor's job, not a policy setting.

AUTO

It comes back on its own

After a power cut or a reboot the machines restart, unlock their storage and bring your server back up with nobody touching anything. Tested by pulling the plug, not assumed.

AES-256

One encryption key per customer

Every volume belonging to you — your disk, your snapshots, the image it was built from — sits under one AES-256 key that is yours alone, not a key shared across the platform. The key is held separately from your storage, readable only by the host's root account.

ART. 17

Deletion that is provable

Closing your account destroys your key. Everything written under it becomes unreadable at once — not deleted-and-trust-us, but cryptographically gone, without us having to promise we found every copy. An automated test creates a customer, destroys it, and fails if the key or any volume survives.

7 DAYS

Logs forget on a schedule

Access logs contain IP addresses, which are personal data. They are deleted after seven days by a rotation policy set on day one, not by someone remembering to run a cleanup.

APPEND

An audit trail nobody can rewrite

Every privileged action is recorded twice: to a log the platform has no permission to modify, and to a second log on the machine that runs your server. Compromising the website does not let anyone erase the record of what was done with it. It records what happened, never your content.

ISOLATED

Separate networks, not shared ones

Each customer gets their own network segment and address range, with a kernel-level rule that drops traffic between customers. A test creates two customers and tries to reach one from the other; if it ever succeeds, the build fails.

CH ONLY

No foreign dependency in the path

No analytics, no tracking, no telemetry service reading what you do. Your data is on Swiss hardware and stays there.

One honest exception during the beta: the public web address is currently delivered through Tailscale, a US company. Connections are encrypted end to end and decrypt only on our machine, so they cannot read the contents — but the connection metadata passes through them. That goes away when real transit is in place, and it is listed under Limits.

Limits

What this does not do yet

A hosting provider that only lists its strengths is telling you half of something. These are the gaps as of today.

No production network transit. The public address runs through Tailscale Funnel — a US company's relay network, on a residential connection. Traffic is encrypted end to end and decrypts only on our hardware, but the metadata does not stay in Switzerland, and Tailscale's own terms do not license Funnel for commercial hosting. Until real transit and dedicated IP space are in place, there is no uptime commitment worth signing.

We hold your encryption keys. That is what lets your server reboot at 03:00 without you. It means encryption protects you against a stolen or discarded disk and makes deletion provable — it does not stop us reading a running machine. Nobody running your workload can honestly claim otherwise without specialised server hardware we do not have. If you would rather hold the key yourself, ask: it is possible, and the trade is that your server waits for you after every power cut.

No failover between machines. Two machines run customer servers, and the platform decides which one you land on — but they are deliberately independent rather than clustered, because a two-machine cluster fails as one unit rather than half. If the machine holding your server goes down, your server is down until it comes back.

There are no backups. Not offsite, not onsite, not yet. If a disk fails or a machine is destroyed, the data on it is gone — and because each server's disk is encrypted with its own key, it is gone thoroughly. Keep your own copy of anything you cannot lose. This is the single biggest gap here and it is being worked on.

No DDoS scrubbing. A sustained attack would take the platform offline. Hyperscalers absorb this; we currently cannot.

Support is one person. Fast and direct during working hours, and honestly nothing at 03:00 on a Sunday.

Private beta

Tell us what you would move first

We are looking for a small number of Swiss companies with a real workload — a file server, an internal tool, a database that should not be in Virginia.

Choose a plan and sign up

Or create an account directly on the smallest plan:

Your address is stored to reply to you and nothing else. No newsletter, no third party, deleted on request. At least 12 characters — length beats symbols. The SSH key is optional and is the public half — the contents of your .pub file, never the private one. Leave it blank and your server is still built — you reach it through the terminal in your browser either way. The key is for connecting with your own SSH client once public access exists.