Modern applications need more than web space.
Containers, workers, databases, AI services and automated deployments do not run on a classic hosting package. We give you the right server for them: as a root server for your team or fully operated by us, with security modules for NIS2. From our data centre in Innsbruck, Austria.
- DC3 data centre, Innsbruck
- Docker-ready from day one
- Managed or unmanaged
- Modules for NIS2
A typical stack today
Yesterday’s website was a folder of PHP files. Today’s application is a system.
A shop connected to its ERP, a headless CMS with its own frontend, an AI assistant or a customer portal consist of several services working together. That takes guaranteed resources, a free choice of runtime and operations that do not leave security to chance.
Classic web hosting
- Shared resources, your neighbour slows you down
- PHP and MySQL in whatever version the provider chooses
- Upload via FTP, changes made directly on the live system
- No background processes, no services of your own
- Security means: “the provider will take care of it”
Servers and containers
- Guaranteed vCPU, RAM and SSD just for you
- Any runtime in any version, isolated as a container
- Deployment via Git and pipeline, with staging and rollback
- Workers, queues, search index and AI services side by side
- Security you can prove: scans, logs, alerts, reports
You decide who looks after the server.
Same hardware, same data centre, same firewall. The difference is who installs updates, gets the alert at night and acts when something goes wrong.
Full control for your team
For development teams and agencies who run their own servers.
- Root access via SSH, you decide everything
- Ubuntu 26.04 LTS, with Docker preinstalled on request
- Fortigate firewall in front of the server
- Provisioned within a few working days
- Security modules can still be added
We operate, you build
For companies who want a running application, not server administration.
- Operating system and security updates by us
- Round-the-clock monitoring, alerts come to us
- Baseline hardening: key-only SSH, no exposed services
- Backup restores tested regularly
- A contact in Innsbruck who knows your server
| Who does what? | Unmanaged | Managed |
|---|---|---|
| Hardware, network, firewall, power | web-crossing | web-crossing |
| Operating system updates | you | web-crossing |
| Keeping Docker Engine and reverse proxy up to date | you | web-crossing |
| Monitoring and response to outages | you | web-crossing, round-the-clock monitoring |
| Setting up backups and testing restores | you, or add a backup | web-crossing, backup is mandatory |
| Your application and its dependencies | you | you, or add container operations |
| Root access | yes | by arrangement |
Three sizes to start from, each one expandable.
Guaranteed resources, SSD storage only, flat-rate traffic and at least one public IPv4 address. Put together operations and extras in the configurator.
Server S
For single applications, staging and development environments.
€45/ month
excl. VAT, unmanaged
- 2 vCPU
- 4 GB RAM
- 250 GB SSD
- 1 IPv4 address
Server M
For Docker stacks with several services, shops and portals.
€59/ month
excl. VAT, unmanaged
- 4 vCPU
- 8 GB RAM
- 500 GB SSD
- 1 IPv4 address
Server L
For large applications, AI services, search indexes and heavy load.
€95/ month
excl. VAT, unmanaged
- 8 vCPU
- 16 GB RAM
- 1 TB SSD
- 2 IPv4 addresses
Larger servers, dedicated hardware and colocation of your own hardware are quoted individually. Minimum term 12 months, renewed for 12 months at a time, cancellable up to 30 days before expiry.
A server that understands your containers from the start.
With the Docker option you do not get a bare server but a ready container platform. Bring your compose.yaml, the rest is in place.
Docker and Compose
Current Docker Engine from the official repository, Compose, proper log rotation and networks separated per project.
Reverse proxy with TLS
New subdomain, new container: the certificate is issued automatically via Let’s Encrypt and renewed without anyone having to remember.
Deployment from Git
Connected to your pipeline in GitLab or GitHub: push, build, deploy. With a dedicated deploy key instead of a shared root password.
Staging next to live
A second stack with its own address for testing. What works there goes live exactly the same, because it is the same images.
Rollback in minutes
Versioned images and backed-up volumes: if an update goes wrong, the previous version is running again quickly.
Container operations (managed)
On request we also look after the containers: updating base images, watching health checks, restarting crashed services and keeping you informed.
Security you can prove.
Since 1 October 2026 Austria’s NIS Act 2026 has been in force, transposing the EU NIS2 Directive. Companies in scope must implement risk management measures, handle vulnerabilities and report significant incidents. And they must look after the security of their suppliers.
This also affects businesses that are not in scope themselves: anyone supplying a company in scope receives supply chain security questionnaires. With our modules you can answer them with evidence.
Vulnerability scan (CVE)
Daily check of all installed packages and container images against public vulnerability databases. Rated by severity, critical findings reported immediately.
SIEM and intrusion detection
Central collection of security logs, analysed for patterns such as login attacks, new admin accounts or modified system files. Real-time alerts, logs stored tamper-proof.
Attack prevention
Automatically detects and blocks brute-force attempts, scanners and known attacker addresses before they reach your application. Adds the application layer to the Fortigate firewall.
Server hardening with report
One-off hardening of operating system and Docker following recognised guidance such as the German BSI IT-Grundschutz, with a report on every measure. The document auditors and customers ask for.
Immutable backup
Off-server backup that cannot be deleted or encrypted even with stolen credentials. The most important insurance against ransomware.
NIS2 evidence
Monthly security report, documented measures for your risk analysis, answers for supplier questionnaires and support with the technical facts when an incident has to be reported.
Our modules cover technical measures. Whether your company falls under the NIS Act is your own assessment. Responsibility for risk management and reporting stays with management. We provide the technology and the evidence.
Build your server.
Choose size, operations and the extras you need. The price updates instantly, and your selection goes straight into your enquiry.
Indicative price without guarantee, excl. VAT, minimum term 12 months. You get the binding quote after a short conversation.
From first conversation to a running stack.
Conversation
What should run, who administers it, what do your customers require? This becomes a fixed-price quote.
Provisioning
Server in our Innsbruck data centre, firewall rules, key-based access, Docker platform and backup on request.
Migration
We move your application or set up the pipeline, test on staging and then switch over.
Operations
Managed: we monitor and update. With security modules you get the report every month.
Frequently asked questions
Do I really need a server instead of web hosting?
For a classic TYPO3, WordPress or Contao website our web hosting is still a good fit. You need a server as soon as background processes, your own services, containers, a specific runtime version or guaranteed performance come into play. If in doubt, we will tell you honestly what is enough.
What is the difference between managed and unmanaged?
With unmanaged we provide hardware, network and firewall, and you look after everything on the server. With managed we take care of the operating system, updates, monitoring, backup and response to incidents. Your application itself stays yours, unless you add container operations.
Can I switch from unmanaged to managed later?
Yes. We review the server once, bring it up to our standard and then take over operations. The effort depends on its condition and is part of the quote.
Is my company covered by NIS2?
Austria’s NIS Act 2026 mainly affects medium-sized and large companies in certain sectors, such as energy, transport, health, digital infrastructure, food or manufacturing. You carry out the assessment yourself. The indirect case is more common: a customer in scope asks you as a supplier for evidence. That is exactly what the modules are for.
Does the NIS2 bundle make me compliant?
No, and no hosting provider can promise that. NIS2 also requires organisational measures such as risk analysis, training and reporting processes, for which management is responsible. Our modules implement part of the technical measures on your server and give you the evidence for them.
Why a paid certificate when Let’s Encrypt is free?
Technically both encrypt equally well. Paid certificates such as RapidSSL are valid for a year, come with an issuer warranty and are sometimes required by partners, banks or in tenders. OV and EV certificates also validate your company.
Where are the servers?
In our own server room in the DC3 data centre in Innsbruck, with uninterruptible power supply, redundant internet connectivity and a Fortigate firewall. The data on your server stays in Austria, and a data processing agreement is included.
Is there funding available?
Ongoing hosting costs are generally not funded. One-off IT security projects such as hardening and a security concept may be eligible under the Tyrolean digitalisation grant. Important: the application must be submitted before placing the order. Ask us about it in the first conversation.
Let’s talk about your application.
In a short conversation we clarify which server fits, who operates it and what evidence your customers expect. No obligation.
or email us at info@web-crossing.com