Know where your documents are processed.
Our target is a document chain hosted and operated in Switzerland: files, backups, indexes and AI processing. Infomaniak has been selected for this future environment; the table below sets out the role of each service.
What ‘Switzerland’ covers, and what it does not
A European user inevitably accesses their data from a device outside Switzerland. Internet traffic, DNS, certificate authorities and certain means of payment may involve third parties or other countries. The precise target is server-side document storage and processing in Switzerland, not the absence of every single byte beyond the border.
Infrastructure and responsibilities
| Data flow | Proposed decision |
|---|---|
| Public presentation website | Current hosting retained, separate from future document storage |
| Document API, database, objects, GPU | Infomaniak in Switzerland for the future document environment |
| Drive keys | Swiss KMS or HSM, or a managed and audited solution within this scope |
| Separate backup | Infomaniak in Switzerland, separate account and administration rights |
| Logs and monitoring | Self-hosted collection in Switzerland, with no document content |
| Transactional email | Infomaniak mailbox, sending via Resend; minimal messages, no document attachments |
Infomaniak has been selected for future document hosting and backups. Deployment includes verifying location, permissions, retention and restoration. Separate accounts reduce certain risks but do not amount to independence between providers. Storage acceptance includes deletion, versioning and recovery tests with the actual administrative roles.
Legal framework
Hosting in Switzerland does not place data beyond the reach of applicable law. Valid legal requests must be handled according to the relevant procedures. Switzerland has mechanisms for international mutual legal assistance; this is not immunity.
The security file handed over at deployment
- Map of data flows and countries crossed
- List of subcontractors and their roles
- Employee access policy
- Security reporting procedure
- Summary of audits actually completed, with their dates
The file brings together the checks carried out, with their dates and scope, the access procedures, the security contacts and the agreed support commitments.