Private cloud on your hardware

Your business data belongs to you.

BauConcept deploys a private, VPN-protected workplace cloud for small and medium-sized businesses — without exposing the cloud application to the public Internet and without hosting customer data on BauConcept servers.

01Customer-owned hardware02VPN-only access03Fully documented
Closed private cloud architecture on customer-owned hardware
VPN Tunnelencrypted
Customer sitedata local
ZERO-TRUST ACCESSON-PREMISES DATAWIREGUARD VPNDOCUMENTED OPERATIONSZERO-TRUST ACCESS
The challenge

Collaboration needs cloud capabilities. Control requires a different architecture.

SMEs need central files, sharing and mobile collaboration. At the same time, sensitive project and customer data should not sit on uncontrolled third-party infrastructure or behind permanently public login pages.

01

Third-party data hosting

Files, plans and contracts are stored on infrastructure and access paths the customer does not directly control.

02

Public attack surface

Cloud logins and web portals remain reachable from the Internet even when they are not needed.

03

Undefined operations

Backups, updates, permissions and recovery procedures are often not reviewed or documented consistently.

The BauConcept architecture

Intentionally closed. Precisely accessible.

The workplace cloud is not a public web portal. Only a configured device with a valid WireGuard connection can reach the internal service. Hardware, data and access keys remain under the customer’s control.

  • VPN-onlyNo public Nextcloud login
  • Private DNS & TLSInternal name resolution and controlled certificates
  • On-PremisesServer and storage remain at the customer site
  • Operational ReadyBackup, maintenance and incident procedures are documented
VPN-only architecture diagram
01

Only authorised devices can reach the private workspace.

Deployment Kit

Not improvised IT. A repeatable deployment and operating standard.

The Deployment Kit combines technical implementation, security logic, documentation and structured handover in one clear project model.

Deployment Kit
01Assessment
02Deployment
03Hardening
04Handover
STANDARD

Standardised deployment

Defined phases, technical checklists, controlled configuration and verifiable acceptance.

SECURITY

Closed security perimeter

VPN users, firewall rules, private DNS, roles and hardening review.

OPERATIONS

Operational readiness

Backup concept, update process, incident manual, administrator briefing and handover.

Three operating models

Deploy. Maintain. Operate.

Every model runs on hardware located at the customer site. BauConcept does not host customer data on its own servers.

01 / SETUP

Private Cloud Setup

One-time deployment on suitable customer-owned hardware.

  • Server and storage baseline
  • Nextcloud AIO
  • WireGuard and firewall
  • Backup baseline
  • Administrator documentation
View scope →
03 / MANAGED

Managed Private Cloud

Remote operation by BauConcept while infrastructure remains on site.

  • Ongoing administration
  • Proactive operating process
  • User and permission management
  • Backup and recovery control
  • Defined service boundaries
View scope →
Project process

From initial assessment to an operational environment.

Each phase ends with a defined result, keeping scope, responsibility and technical decisions transparent.

01

Assessment

Users, data, hardware, access paths and operating model.

02

Deployment

Server, Nextcloud, VPN, firewall, DNS and backup.

03

Hardening

Permissions, access, tests, security and recovery review.

04

Handover

Documentation, briefing and optional operating agreement.

Next step

Is your existing hardware suitable?

The Private Cloud Assessment reviews user count, data structure, existing infrastructure and the appropriate operating model.

Request a Private Cloud Assessment