Managed Keycloak – from Switzerland
Enterprise Identity and Access Management on Swiss cloud infrastructure. VSHN operates your Keycloak instances with 24/7 support and up to 99.99% availability SLA. Inventage provides expert-level Keycloak engineering and consulting. From CHF 360 per month.
Keycloak Expertise from Inventage
Inventage operates the Keycloak Competence Center Switzerland and provides Level 3 engineering support for your Keycloak deployment. Their engineers build custom extensions, resolve complex configuration issues, and contribute to the Keycloak project. Clients include Baloise, LGT, VP Bank, Zürich Insurance, and the Swiss Federal Office of Information Technology.
24/7 Operations by VSHN
VSHN operates your Keycloak instances — monitoring, patching, upgrades, incident response, and backup management. Our ISO 27001-certified operations team provides round-the-clock coverage so your identity infrastructure is always available.
Digital Sovereignty & Swiss Hosting
Identity is the foundation every other service depends on — it is the starting point for any digital sovereignty initiative. Managed Keycloak runs on Swiss cloud providers (cloudscale.ch, Exoscale), on Enterprise Private Cloud, or on your own on-premises infrastructure — your identity data stays where you control it. And because Keycloak is open source, you are never locked in to VSHN — you can change service providers at any time.
Self-Service on Servala
Order managed Keycloak instances through Servala with automated provisioning on eight cloud providers, including Enterprise Private Cloud and on-premises. Choose between Best Effort for development workloads or Guaranteed Availability with 99.99% SLA for production. PostgreSQL database, TLS encryption, and automated backups included.
Enterprise IAM Features
Consolidate authentication across your organisation with Single Sign-On, multi-factor authentication, and federation with LDAP or Active Directory. Keycloak supports up to 100 realms with unlimited users, custom themes, and standards-based protocols (OAuth 2.0, OpenID Connect, SAML 2.0) for integration with any application.
Open Source — No Lock-in
Keycloak is licensed under Apache 2.0, originally created by Red Hat and now a CNCF incubating project. Standards-based protocols (OAuth 2.0, OpenID Connect, SAML 2.0) mean your integrations work with any provider. Your realms, users, and configuration belong to you — not to your service provider.
Managed Keycloak pricing
Cloud provider computing resources charged separately. PostgreSQL database included. Business hours support included; 24/7 support plan optional.
Contact us for a requirements analysisWhat VSHN and Inventage deliver
24/7 operations and monitoring by VSHN
Expert Keycloak engineering by Inventage
Automated daily backups with encrypted off-site storage
Continuous upgrades to the latest Keycloak version
Security patches applied proactively
Deployment on cloudscale.ch, Exoscale, Enterprise Private Cloud, on-premises, and additional providers via Servala
Custom themes, extensions, and enterprise integrations supported
Consulting and onboarding package available (CHF 8,000 / 5 days)
Managed Keycloak FAQ
What is Keycloak?
Keycloak is an open-source Identity and Access Management (IAM) solution that provides Single Sign-On (SSO), multi-factor authentication, social login, user federation with LDAP and Active Directory, and fine-grained authorisation. It supports industry-standard protocols including OAuth 2.0, OpenID Connect, and SAML 2.0. Keycloak is backed by Red Hat and is a CNCF incubating project, licensed under Apache 2.0.
Who operates managed Keycloak?
VSHN provides Level 2 operations — 24/7 monitoring, infrastructure management, patching, upgrades, backups, and incident response. Inventage provides Level 3 engineering support — expert analysis of Keycloak configuration, custom extensions, and core product issues. Together, this three-tier model (your team for Level 1 end-user support, VSHN for operations, Inventage for engineering) covers the full support stack.
What SLA is available for managed Keycloak?
The Best Effort plan at CHF 360 per month includes professional operations without a formal uptime commitment — suitable for development and staging environments. The Guaranteed Availability plan at CHF 1,500 per month provides 99.99% uptime SLA with two Keycloak instances and a PostgreSQL database, backed by 24/7 engineer support. A dedicated test and development instance is included at Best Effort tier.
Which cloud providers are supported?
Managed Keycloak is available on Swiss cloud providers including cloudscale.ch and Exoscale, both operating data centres exclusively in Switzerland. Through Servala, Keycloak is also available on Xelon, Switch, Levigo, APPUiO, Managed OpenShift, and Enterprise Private Cloud. Swiss providers are recommended for organisations with data residency requirements.
How are backups handled?
All Keycloak data is stored in a managed PostgreSQL database. Automated daily backups run at 22:00 with six retained copies and up to 500 GiB of cumulative storage. Backups are encrypted at rest. VSHN uses CloudNativePG with Barman for backup orchestration. Deletion protection is available as an additional safeguard.
Can I use custom themes and extensions?
Yes. Managed Keycloak supports custom themes for login pages, account management, and email templates — including logos, colours, fonts, and custom stylesheets. Custom extensions are supported via container images. Inventage develops custom authenticators, event listeners, protocol mappers, and federation providers as part of their Level 3 engineering service.
What Keycloak features are included?
Each managed Keycloak instance supports up to 100 realms with unlimited users, admin console access, built-in metrics and dashboards, custom subdomain configuration, keycloak-config-cli for declarative configuration, and TLS-encrypted PostgreSQL database. High-availability configurations use Infinispan clustering across two or three instances with zero-downtime maintenance.
Why is managed Keycloak important for digital sovereignty?
Identity is the service every other application depends on for authentication and authorisation. Choosing an open-source IAM solution hosted in Switzerland means your identity infrastructure is not controlled by a foreign cloud vendor. With managed Keycloak, your data stays on Swiss cloud providers (cloudscale.ch, Exoscale), your configuration is portable because Keycloak uses open standards (OAuth 2.0, OpenID Connect, SAML 2.0), and you are never locked in to VSHN — you can migrate to another provider or self-host at any time. This makes Keycloak the natural foundation for a digital sovereignty strategy.
How does managed Keycloak compare to self-hosted?
Self-hosting Keycloak requires Kubernetes expertise, database administration, backup automation, security patching, and on-call coverage. Managed Keycloak provides all of this as a service with a fixed monthly fee. VSHN handles the infrastructure and operations while Inventage provides engineering expertise that would be difficult to build in-house. For production workloads, the Guaranteed Availability plan includes 99.99% SLA and 24/7 support.
How do I get started?
The fastest way is to order managed Keycloak through Servala at servala.com/service/keycloak/ — self-service provisioning on your choice of cloud provider. For enterprise deployments with custom requirements, contact us using the form below. VSHN and Inventage offer a consulting and onboarding package (CHF 8,000 for 5 days, 40 hours) covering architecture design, realm configuration, identity provider integration, and theme customisation.
Contact us
Need managed Keycloak or IAM consulting? Order on Servala at servala.com/service/keycloak/, or contact us for a free initial consultation with VSHN and Inventage.
Book a free callOr send us a message