Swiss Data Residency
Most consulting firms access AI through shared public APIs. In those environments — ChatGPT, standard cloud-based Claude, Gemini — prompts and uploaded documents may be retained, logged, or used for model improvement. This practice does not operate that way.
All AI processing is physically pinned to Switzerland, inside Exoscale data centres in Geneva and Zurich.
- —Jurisdiction: Swiss Federal Act on Data Protection (FADP) exclusively. No cross-border data transfer for processing.
- —Foreign surveillance protection: Data is not subject to the US CLOUD Act or equivalent third-country instruments.
- —No commingling: Client data is stored in a dedicated, encrypted PostgreSQL database — isolated from all other client engagements.
Dedicated Inference
The AI reasoning engine is a dedicated instance of the GLM-5 high-reasoning model, running on rented hardware. It is not a shared API. The AI provider has no access to prompts, documents, or outputs.
- —Zero data retention: Nothing is logged externally. Prompts and responses exist only within the dedicated environment.
- —No training use: Client data is never used to train or fine-tune any AI model — current or future. Strategic vulnerabilities, internal communications, and sensitive assessments remain the exclusive intellectual property of the client.
Isolated Execution
Every analysis, code execution, or document processing task runs inside a single-use sandboxed container. When the task ends, the environment is permanently deleted. No residual state carries between sessions.
- —One-time containers: Each task spawns a fresh environment. It processes. It ends. It is deleted.
- —Prompt injection protection: Sandboxed execution prevents cross-contamination between document content and system behaviour.
- —No sub-processors: Client data is not passed to secondary AI tools, plugins, or third-party services without explicit written consent.
Continuous Control
Full administrative control of the infrastructure is maintained at all times. No third-party intermediary holds access.
- —Hard-wipe capability: At project close, the dedicated instance and database can be fully purged. Zero residual data guaranteed.
- —Audit trail: Every AI action is logged in a private internal ledger, available to the client on request under the applicable Non-Disclosure Agreement.
Capability Summary
| Capability | Detail | Status |
|---|---|---|
| Data residency | Switzerland (Exoscale, Geneva/Zurich) | ●Active |
| Legal framework | Swiss FADP — no cross-border transfer | ●Active |
| Dedicated inference | GLM-5 high-reasoning, isolated hardware | ●Active |
| Zero data retention | No external logging of prompts or outputs | ●Active |
| Training exclusion | Client data never used for model training | ●Active |
| Sandboxed execution | Single-use containers, deleted on completion | ●Active |
| Hard-wipe capability | Full deletion at project close on request | ●Active |
| Audit trail | Private internal log, available under NDA | ●Active |