Encrypted data residency in Zurich · Swiss key sovereignty · revDSG, GDPR and the EU AI Act · operated on infrastructure certified to ISO 27001 and SOC 2 Type II
Everything that is stored stays encrypted in Switzerland.
Your own digital vault. Without our release, your AHV numbers and IBANs stay unreadable.
Our database is not reachable from the open internet.
The AI works under applicable data protection law, and your data never leaves Switzerland and the EU.
Every tenant is technically separated. Two-factor login is mandatory.
Every access is logged, immutable for 10 years.
Daily backups, encrypted as well, stay in Switzerland.
Files are never public. Upload links are valid for a maximum of 15 minutes.
Audited infrastructure in line with Swiss, EU and international standards.
Access, deletion, export. Completed within 30 days.
Contracts, training and registers in line with Swiss data protection law.
Every product change is checked against a catalogue of fixed security gates before going live, automated and audit-proof.
A dedicated channel is available for security researchers and due diligence enquiries.
Controller: SOTHURA SAFE GmbH, Wassergasse 5, 4573 Lohn-Ammannsegg, Switzerland.
Security reports: security [at] sothura [dot] com, encrypted preferred. Data protection enquiries: datenschutz [at] sothura [dot] com.
We respond to qualified reports within three business days. Please provide a clearly described reproduction path, the affected component and — where possible — an assessment of the impact.
Safe Harbor. We will not pursue security researchers under civil or criminal law as long as (i) the report is made in good faith, (ii) only your own test accounts are used, (iii) no third-party customer data is viewed, copied or disclosed, (iv) no denial-of-service tests or social-engineering attacks against employees take place, and (v) a reasonable period for remediation is granted before public disclosure. Unauthorised penetration tests, exploitation of vulnerabilities beyond what is necessary for reporting and the harvesting of third-party data are not permitted and will be prosecuted under criminal law (Art. 143, 143bis, 144bis CC).