Trust centre
Security and data protection
This platform is built for organisations with high confidentiality requirements — public authorities, law firms and advisory practices in Switzerland. Developed in Switzerland: AI processing runs sovereignly in Switzerland, while the application and data are hosted GDPR-compliant in the EU (Germany) and never leave the platform.
Core principles
Data residency EU, AI in Switzerland
The application and storage run GDPR-compliant in a certified data centre in the EU (Germany). AI processing runs sovereignly on our own infrastructure in Switzerland. Your content never leaves the platform.
Local processing
Document content is processed within the platform. No content is forwarded to external providers.
Encryption
Data is encrypted in transit and at rest. Backups are stored with additional encryption.
Tenant isolation
Every organisation is strictly separated at the database level. Access is enforced row by row; cross-access to other organisations is technically excluded.
Tamper-evident audit trail
Security-relevant events are logged in a tamper-evident way. Entries are chained and append-only; subsequent changes are detectable.
Secured backups
Daily encrypted backups with regular restore testing protect against data loss.
Control matrix
Each risk is mapped to a concrete measure and verifiable evidence. The references point to the EU General Data Protection Regulation (GDPR) and the Swiss Data Protection Act (revDSG), the international standard ISO/IEC 27001, and the guidance of the National Cyber Security Centre (NCSC).
| Risk | Measure | Evidence | Reference |
|---|---|---|---|
| Data outflow to US hyperscalers | Storage GDPR-compliant in the EU (Germany), AI processing sovereignly in Switzerland. No US cloud providers in the data path. | Contractual data-residency assurance, data processing agreement (DPA), architecture documentation. | revDSGISO 27001 |
| Disclosure to external services | Content is processed locally; no content outflow to third parties. | Network segmentation, controlled outbound connections. | revDSGNCSC |
| Interception in transit | End-to-end transport encryption, encryption of data at rest. | Encryption configuration, encrypted backups. | ISO 27001NCSC |
| Mixing of organisation data | Strict per-organisation isolation at database level, enforced row by row. | Access policies, isolation test reports. | revDSGISO 27001 |
| Undetected tampering | Tamper-evident audit trail with chained checksums. | Checksum-chain verification, audit export. | revDSGISO 27001 |
| Data loss | Daily encrypted backups with restore testing. | Backup logs, restore-test reports. | ISO 27001NCSC |
| Unauthorised account access | Multi-factor authentication (enforceable by the organisation), single-session control. | Two-factor enforcement setting, session log. | revDSGISO 27001 |
| Malware via uploads | Automatic malware scan of every uploaded file before processing. | Scan log, rejection of infected files. | ISO 27001NCSC |
| Answers without source grounding | Every answer is checked against the provided sources; without evidence it is refused. | Source markers in every answer. | revDSG |
- Measure
- Storage GDPR-compliant in the EU (Germany), AI processing sovereignly in Switzerland. No US cloud providers in the data path.
- Evidence
- Contractual data-residency assurance, data processing agreement (DPA), architecture documentation.
- Measure
- Content is processed locally; no content outflow to third parties.
- Evidence
- Network segmentation, controlled outbound connections.
- Measure
- End-to-end transport encryption, encryption of data at rest.
- Evidence
- Encryption configuration, encrypted backups.
- Measure
- Strict per-organisation isolation at database level, enforced row by row.
- Evidence
- Access policies, isolation test reports.
- Measure
- Tamper-evident audit trail with chained checksums.
- Evidence
- Checksum-chain verification, audit export.
- Measure
- Daily encrypted backups with restore testing.
- Evidence
- Backup logs, restore-test reports.
- Measure
- Multi-factor authentication (enforceable by the organisation), single-session control.
- Evidence
- Two-factor enforcement setting, session log.
- Measure
- Automatic malware scan of every uploaded file before processing.
- Evidence
- Scan log, rejection of infected files.
- Measure
- Every answer is checked against the provided sources; without evidence it is refused.
- Evidence
- Source markers in every answer.
Further information
The legal basis and processing details are set out in our legal documents. For security questionnaires or an in-depth review, please get in touch with us.
As of: 2026-08-25