Skip to content
UeliUeliAssistent

Trust centre

Security and data protection

This platform is built for organisations with high confidentiality requirements — public authorities, law firms and advisory practices in Switzerland. Developed in Switzerland: AI processing runs sovereignly in Switzerland, while the application and data are hosted GDPR-compliant in the EU (Germany) and never leave the platform.

Core principles

Data residency EU, AI in Switzerland

The application and storage run GDPR-compliant in a certified data centre in the EU (Germany). AI processing runs sovereignly on our own infrastructure in Switzerland. Your content never leaves the platform.

Local processing

Document content is processed within the platform. No content is forwarded to external providers.

Encryption

Data is encrypted in transit and at rest. Backups are stored with additional encryption.

Tenant isolation

Every organisation is strictly separated at the database level. Access is enforced row by row; cross-access to other organisations is technically excluded.

Tamper-evident audit trail

Security-relevant events are logged in a tamper-evident way. Entries are chained and append-only; subsequent changes are detectable.

Secured backups

Daily encrypted backups with regular restore testing protect against data loss.

Control matrix

Each risk is mapped to a concrete measure and verifiable evidence. The references point to the EU General Data Protection Regulation (GDPR) and the Swiss Data Protection Act (revDSG), the international standard ISO/IEC 27001, and the guidance of the National Cyber Security Centre (NCSC).

Data outflow to US hyperscalers
Measure
Storage GDPR-compliant in the EU (Germany), AI processing sovereignly in Switzerland. No US cloud providers in the data path.
Evidence
Contractual data-residency assurance, data processing agreement (DPA), architecture documentation.
revDSGISO 27001
Disclosure to external services
Measure
Content is processed locally; no content outflow to third parties.
Evidence
Network segmentation, controlled outbound connections.
revDSGNCSC
Interception in transit
Measure
End-to-end transport encryption, encryption of data at rest.
Evidence
Encryption configuration, encrypted backups.
ISO 27001NCSC
Mixing of organisation data
Measure
Strict per-organisation isolation at database level, enforced row by row.
Evidence
Access policies, isolation test reports.
revDSGISO 27001
Undetected tampering
Measure
Tamper-evident audit trail with chained checksums.
Evidence
Checksum-chain verification, audit export.
revDSGISO 27001
Data loss
Measure
Daily encrypted backups with restore testing.
Evidence
Backup logs, restore-test reports.
ISO 27001NCSC
Unauthorised account access
Measure
Multi-factor authentication (enforceable by the organisation), single-session control.
Evidence
Two-factor enforcement setting, session log.
revDSGISO 27001
Malware via uploads
Measure
Automatic malware scan of every uploaded file before processing.
Evidence
Scan log, rejection of infected files.
ISO 27001NCSC
Answers without source grounding
Measure
Every answer is checked against the provided sources; without evidence it is refused.
Evidence
Source markers in every answer.
revDSG

Further information

The legal basis and processing details are set out in our legal documents. For security questionnaires or an in-depth review, please get in touch with us.

As of: 2026-08-25