Security for the most sensitive documents in energy.
Stored in Zürich, Switzerland. Encrypted. Never used to train AI.
Data rooms, contracts and financial models decide transactions. Yours are stored in Zürich, encrypted in transit and at rest, never used to train AI, and reachable only by the people you name.
- Stored in Zürich, Switzerland
- TLS 1.3 in transit · AES-256 at rest
- Never used to train AI — contractual
- GDPR · Swiss FADP
- NDA before any upload
- Row-level access, enforced by the database
- Expert-approved due diligence reports
- ISO/IEC 27001 · SOC 2 Type II certified infrastructure
Stored in Switzerland. Served from Germany.
Zürich, Switzerland
Client documents, generated reports and backups.
Frankfurt, Germany
Database, authentication and application servers.
Network edge
TLS termination and DDoS protection. No client documents are stored at the edge.
AI analysis runs under enterprise terms with contractual no-training and no-retention commitments: nothing you upload is used to train a model, and nothing is kept for the provider's own purposes. Your documents remain stored in Switzerland, and no client document, data-room file or report is ever sent to any other AI provider.
Four steps, in this order, every time.
- Step 1
1NDA first
A mutual non-disclosure agreement is signed before any confidential data moves.
- Step 2
2Sealed transfer
Documents go directly into your private, encrypted workspace.
- Step 3
3Scoped access
Only the people you name — on your side and ours — can reach the engagement. Access is granted per project.
- Step 4
4Your deliverable
Outputs belong to you and are delivered through the same controlled workspace.
What protects your data.
The same technical and organisational measures we commit to in writing with every client.
Access
Role-based access on the principle of least privilege, with individual named accounts for everyone who touches client data. Tenant data segregated at the database layer by row-level policies the database enforces itself — a request carrying one client's identity cannot read another's rows.
Documents
Held in private storage that is not publicly readable. Served only through time-limited signed links, issued after the backend has verified that the requesting user is entitled to that specific file.
Encryption
TLS 1.3 or higher in transit. AES-256 at rest. Keys managed by the infrastructure providers.
Integrity and logging
Every change to client data is attributable to an authenticated user. Administrative and privileged operations are logged. Data-modifying interfaces validate their inputs.
Resilience
Redundant infrastructure across availability zones. Continuous database backup with point-in-time recovery. Restoration tested periodically.
Change and review
Security review is part of the change process for any component that handles client data or authentication. Automated checks run before every deployment; findings rated as errors are fixed before release. Dependencies and configuration are scanned continuously.
People
Written confidentiality obligations for everyone who works with us, surviving their departure. Annual data-protection training.
Speed and depth from AI. Judgement from industry experts.
AI provides the speed and the depth; human industry experts provide the judgement — and approve every due diligence report. Every supervised due diligence report is reviewed and approved by a qualified advisor before it is issued, and says so on its face. Self-service analyses are yours to run at any time, built to support the professional judgement of the people using them.
Built to the standard, run on certified infrastructure.
Our security controls are built to the ISO/IEC 27001 and SOC 2 control families — access control, encryption, logging, incident response, vendor management, backup and personnel security — and are written into every agreement we sign.
The infrastructure that stores and processes your data is independently certified: SOC 2 Type II across every provider that stores or processes client data, and ISO/IEC 27001 for document storage and the database.
- Document storageISO/IEC 27001 · SOC 2 Type IIZürich, Switzerland
- DatabaseISO/IEC 27001 · SOC 2 Type IIFrankfurt, Germany
- Application hostingSOC 2 Type IIFrankfurt, Germany
Yours to keep.
Ownership
You own everything you upload and everything we produce for you.
Export
Every report and project can be exported at any time.
Retention
Your documents, analyses and reports stay available to you for as long as you use the platform. Nothing expires, and nothing is deleted without your instruction.
Confidentiality
Your projects are visible only to the people you invite. Access is granted per project and can be withdrawn at any time.
See it on one of your own projects.
Bring a live data room. Every document stays in Switzerland from the first upload, and the report arrives approved by a qualified advisor.
Questions about security: [email protected]
