SOTHURA SAFE
← Back to homepage
EN
DEDeutschFRFrançaisITItalianoENEnglish

Frequently asked questions

The German version is binding. This translation is provided for information only.

The questions people ask before a meeting — with the answer in the first sentence · Last updated: August 2026

Below are fourteen questions Swiss brokers ask us regularly, each with its answer. Where an answer rests on our Terms, on the Legal Notice or on the security page, the reference is given alongside, so you can look it up instead of having to take our word for it. What we cannot substantiate is not on this page.

What it is and who it is for

SOTHURA SAFE is the Swiss software platform for insurance advisers and brokers, in personal lines as much as in commercial lines. Advice, acquisition, offer comparison, policy analysis and mandates sit on one platform.

That includes advisory documentation compliant with the ISA — the record of what you advised, and when. Data is held in line with the revDSG (the revised Swiss data protection act) and stays in Switzerland, in Zurich.

No model is trained on your client data.

For Swiss insurance brokers and intermediaries serving personal and commercial clients, from the sole broker to the larger team.

Independent and tied: both work with the same platform. Personal and commercial business sit side by side in one system, instead of in two separate tools.

Smaller offices start in self-service up to and including ten active seats. From eleven seats an individual framework agreement is added (Terms, section 1.5).

Three things: one system instead of several tools, analysis built in rather than bolted on beside it, and your own brand on what clients see.

One system: advice, acquisition, offer comparison, policy analysis and mandates are in one place. What was captured in the policy analysis is available in the offer comparison, without anyone typing it a second time.

Analysis built in: reading a policy is not a separate program alongside, it is a step in the flow. The value that was read out lands where you carry on working anyway.

Your own brand: your logo, your colours, your domain. Your clients see your look and feel throughout, not an anonymous third-party provider.

Security and data protection

Encrypted, in a data centre in Zurich.

Storage is exclusively in Switzerland. No exceptions.

The language model analysis also runs in Zurich. Only in an emergency — if that site fails or is overloaded — does an EU site do the computing instead. Nothing is stored there: the request is processed and that is the end of it. Client, contract and document data never goes to the US or other third countries.

From a Swiss standpoint, EU member states have a level of data protection recognised as adequate by the Federal Council (Art. 16 revDSG). Operated on infrastructure certified to ISO 27001 and SOC 2 Type II — what is certified is the infrastructure, not our company.

What that covers in detail — encryption, access rights and the full list of sub-processors (the service providers that carry out parts of the operation for us) — is set out on the "Security and Data Protection" page.

No, not where location, access and verifiability are settled. Those are exactly the three points that are fixed at SOTHURA SAFE.

What that gives you:

  • Each broker sees only their own data
  • Access is tied to roles — you decide who may see which client
  • Every access is logged and therefore remains demonstrable

Control is therefore not about having a machine in your own office, but about knowing where your data sits, who can see it and what has happened to it. Where it sits is answered above.

No. Neither we nor the providers of the language models in use train anything on your data.

Our Terms (section 6.2) put it in these words: "Transmitted content is processed transiently and is not stored at the model provider. Training the third-party models used on customer data and any review by their staff are contractually excluded."

"Processed transiently" means: the content is used for the answer and not kept afterwards. Because it stands in the Terms, it is part of the contract and not a statement of intent.

Regulation and responsibility

The platform supplies the tool; the regulatory duty stays with you.

What the platform supplies:

  • advisory documentation compliant with the ISA
  • logged access that can be produced as evidence
  • data held in Switzerland, aligned with the revDSG

What it does not take off your hands: the duties that come with supervision. Our Terms (section 11.6) say on this "These duties remain entirely with the customer", and the Legal Notice (section 4) says "supervision of users remains with FINMA and with the supervisory and training bodies applicable to the users".

Hence the wording: on the revDSG, the GDPR, the EU AI Act and FINMA Circular 2018/3 we say "aligned with" and not "compliant with". A tool can be aligned; what is compliant, in the end, is your operation as a whole.

Responsibility for the advice stays with the broker.

Our Terms (section 6.3) say on this: "The customer must independently review, plausibility-check and, where necessary, verify all AI outputs against primary sources before using them vis-à-vis end clients."

So that you can actually exercise that responsibility, the platform is built accordingly: uncertain points are marked and sorted to the top, instead of passing as a settled value. No value travels on without your release, and your correction overwrites the machine-read value.

We deliberately give no accuracy figure in per cent. It would swing widely with document quality, insurer and line of business, and would therefore be advertising rather than information.

Two different periods: access and change logs 10 years, advisory documents 11 years.

The logs stay in Switzerland, kept for 10 years. Every access is logged, unalterable for 10 years.

Advisory documents as well as policy and advisory PDFs are kept for 11 years. The difference comes from when the period starts: the Swiss Code of Obligations requires ten years of retention in Art. 958f, and we add one year of margin, because that period does not start running on the day of the document.

Rollout and technology

In stages: the existing portfolio first, the open cases afterwards.

The handover runs either through a file import or through an interface to your current system. Which field from the old system goes to which field with us is something we settle together during the rollout — that mapping is the part that takes care, not the import itself.

That keeps your day-to-day business workable during the switch: the portfolio is transferred and checked before the first open case moves.

The connection runs through a programming interface (API), not through rebuilding the platform around each third-party system.

For the exchange with insurers we implement the Swiss insurance industry's data standard for contract data: we output contract data in exactly the format that insurers and industry platforms expect — lines of business and companies are named there with the keys that apply across the industry, not with in-house names. What is exchanged therefore has to be neither retyped by hand nor rebuilt for every counterparty.

The platform is likewise aligned with the SAF (Standard API Framework) standard from ecoHub, the shared exchange route of the Swiss insurance industry. The data structures and the transport layer for it are built; no data flows over that channel yet.

Every connection presupposes a clarification: which system, which data, in which direction. That is the normal case and not a limitation — only afterwards is it settled what the interface has to do and who takes on which part. Which of your systems come into question is something we clarify in the rollout meeting.

Our aim is partnerships with the providers of the connected systems, so that connections can be standardised instead of each one being built on its own. We are working on that. Which connection is already in place today depends on the individual system — we will tell you that concretely before you decide.

Alongside that, the simple route stays open: importing existing data from common file formats, for the portfolio and master data. That needs no interface at all.

Yes: your own logo, your own colours, your own domain.

That applies in every view your clients get to see. They see your look and feel throughout, not an anonymous third-party provider. It is set up at the start, together with inviting the team and importing the portfolio.

What is meant is your presence towards your own end clients. Reselling the platform to third parties as your own product is not covered by it (Terms, section 4.2).

Pricing and contract

SOTHURA SAFE costs CHF 149.– per user per month, excluding VAT. Billing is monthly, per active seat.

Anyone signing up by 31 December 2026 pays CHF 129.– per user per month for the first six months ("early bird"). After that the regular price applies. The scope of the service is the same in both cases.

The full range of functions is included: 12 of the 32 modules belong to the base package, further modules are booked on top.

Up to and including ten active seats everything runs in self-service. For larger organisations from eleven seats the provider concludes an individual framework agreement (Terms, section 1.5); pricing is agreed there case by case.

You sign an annual contract: the term is one year, billing is monthly per active seat (Terms, section 14.1). Termination takes effect at the end of the term, with 30 days notice and in text form — an email is enough (Terms, section 14.3). If no such termination is given in time, the contract renews for a further year in each case; the same notice period and the same form apply to every renewal. Miss the deadline and you are tied in for another year. Monthly billing changes nothing about that: it does not shorten the term and does not create a monthly right of termination.

On your data the Terms (section 5.5) say in these words: "The customer may export its customer data at any time in a common machine-readable format (e.g. JSON, CSV). After the contract ends, customer data remains available for export for 30 days. Thereafter it is deleted within 90 days, unless statutory or regulatory retention obligations preclude deletion."

In plain terms: you can get at your data at any time, during the term as well. After the end there is a 30-day window for the export, after which it is deleted — except for records that have to be kept. Which those are and for how long is answered in the question on retention.

The formalities

SOTHURA SAFE GmbH, Wassergasse 5, 4573 Lohn-Ammannsegg, Canton of Solothurn. Registered in the commercial register of the Canton of Solothurn, UID CHE-429.131.582. Management is held by Silvio Siegenthaler and Michel Di Vito, joint signature by two. The full provider identification is set out in the legal notice.

  • Legal notice and provider identification
  • Security and data protection
  • Privacy policy under the revised FADP and GDPR
  • General terms and conditions (B2B)
© 2026 SOTHURA SAFE GmbH. All rights reserved.