Data security
Built to the revised Swiss Data Protection Act: data minimisation, traceable processing, data held in Switzerland. We do not collect what we do not need — what is not collected cannot be lost.
Trust Center
What we promise, we state precisely. What we cannot promise, we say as well — you should never have to guess where your data sits and who sees it.
Hosting and data storage exclusively in Switzerland. AI models running in production are in Switzerland — development and testing deliberately run via a lower-cost provider, exclusively with synthetic data.
Built to the revised Swiss Data Protection Act: data minimisation, traceable processing, data held in Switzerland. We do not collect what we do not need — what is not collected cannot be lost.
Dedicated infrastructure at a Swiss provider instead of a shared environment at a global hyperscaler. Own server, own data, own access paths — no neighbour on the same machine.
TLS on all addresses, HSTS, restrictive security headers. The database deliberately has no open port and is reachable only on the internal network. Updates and fault resolution stay with us.
All transmission is encrypted (TLS). Passwords are hashed with Argon2, never stored. Session cookies are HttpOnly and Secure, access links carry only a hash instead of the token.
Access follows from identity, tenant, role, permission and licence — always checked on the server. Every role gets exactly as much as it needs. With us a hidden button is not protection, only convenience.
Separate data per customer, enforced in the database rather than in the application. There is no way around this separation — not by accident, and not through a forgotten query.
We are not certified and we do not claim to be. The points above describe how we build and operate — you may ask questions and have them checked at any time.