Sovereign, Swiss, Compliant

ISO Security Certifications and Compliance with Industry Standards

Sovereignty by Design


A sovereign cloud guarantees that no foreign government and no overseas company can access, monitor or switch off your infrastructure — whether by legal compulsion or political pressure. Safe Swiss Cloud delivers this from Switzerland, combining European-grade data protection with a jurisdiction that answers to neither Washington nor Brussels.

Legal Sovereignty

A single legal framework applies: Swiss law, recognised by the EU as equivalent to the GDPR. No competing jurisdiction can lay claim to your data.

Operational Sovereignty

Your infrastructure is operated by staff under Swiss jurisdiction. There is no foreign parent company, which can be compelled to grant access to your data.

Political Sovereignty

Genuine sovereignty rests on all five factors working together. Safe Swiss Cloud has been built around them since 2013, and customers on four continents rely on this positioning today.

Data Sovereignty

Your data is stored and processed in Switzerland. Access is governed by Swiss law and lies outside the reach of the US Cloud Act.

Technological Sovereignty

Open standards and open-source platforms keep your workloads portable. You can move between providers without costly re-architecting or vendor lock-in.

Genuine sovereignty rests on all five factors working together. Safe Swiss Cloud has been built around them since 2013, and customers on four continents rely on this positioning today.

100 % Swiss


Safe Swiss Cloud is a privately owned Swiss company. We operate our own data centres exclusively in Switzerland, on infrastructure powered entirely by renewable energy.

Swiss Ownership & Jurisdiction

A privately owned Swiss business with data centres located only in Switzerland. This keeps your data under Swiss law and outside the scope of the US Cloud Act and other foreign access regulations.

Two Swiss Data Centers

Infrastructure runs across two geographically separate data centres in Switzerland. This geo-redundancy keeps mission-critical workloads available even if one site is disrupted.

100 % Renewable Energy

Our data centres have run on 100 % renewable electricity from water and wind for more than ten years. The accounting is TÜV SÜD CMS 89 certified, helping you reduce your CO₂ footprint.

Certified security and compliance


Below you will find an overview of our certifications and the standards we comply with.

Certificates

Information Security Managment

Code of practice for information security controls based on ISO/IEC 27002 for cloud services

Code of practice for protection of Personally Identifiable Information (PII) in public clouds acting as PII processors

TÜV SÜD Standards CMS 89 Accounting: 100% renewable electricity

Security, privacy, data protection and compliance

General Data Protection Regulation of the European Union

Swiss Data Protection Act for the Protection of Personal Data

Outsourcing for banks according to the Swiss Financial Market Supervisory Authority (FINMA)

Circular of the German Federal Financial Supervisory Authority

European Digital Operational Resilience Act for the Financial Sector

FMH recommendations for doctors on the DSG

Health Insurance Portability and Accountability Act

Good Clinical, Laboratory, and Manufacturing Practices

Cloud Computing Compliance Criteria Catalogue of the German Federal Office for IT Security

Network and Information Security Directive 2 of the European Union

Certifications


Internationally recognized certifications for the highest security, data protection and sustainability standards.

ISO 27001

Safe Swiss Cloud has had the ISO 27001 certification for Information Security Management Systems, which includes compliance with the ISO 27018 standard for Personally Identifiable Information (PII) in the cloud since 2015.

It has been audited and had its certification confirmed every year since then.

ISO/IEC 27001:2022 specifies the requirements for the creation, implementation, maintenance and continuous improvement of the information security management system in an organisation. For further details please visit the official ISO 27001 website.

ISO 27017

This standard provides guidance on the information security aspects of cloud computing, recommending and assisting with the implementation of cloud-specific information security controls supplementing the guidance in ISO/IEC 27002 and other ISO27k standards.

The code of practice in this standard provides additional information security controls implementation advice beyond that provided in ISO/IEC 27002, in the cloud computing context.

The standard advises both cloud service customers and cloud service providers, with the primary guidance laid out side-by-side in each section.

ISO 27018

ISO/IEC 27018:2019 defines generally accepted control objectives, controls and guidelines for implementation measures to ensure that personal data is protected in accordance with the privacy principles of ISO/IEC 29100 for Public Cloud Computing Environments. For more details, please visit the official ISO 27018 website. It is an extension of and part of the ISO 27001 certification.

Renewable Energy

Our data centers have been using 100% renewable electricity from water and wind for more than ten years. Since 2024 we have been TÜV certified according to «TÜV SÜD Standards CMS 89 Accounting Renewable Energies (08/2018)». In this way, we support our customers in reducing their CO2 footprint.

Security, data protection and compliance


Safe Swiss Cloud guarantees compliance with strict legal and industry-specific standards for maximum data security and regulatory compliance.

GDPR

The General Data Protection Regulation (EU) 2016/679 (GDPR) is a regulation in EU law on data protection and privacy for all individual citizens of the European Union (EU) and the European Economic Area (EEA). It also addresses the transfer of personal data outside the EU and EEA areas.

Swiss DPA

The Swiss Federal Act on Data Protection (FADP or DPA) is compatible with the EU’s GDPR regulations and specifies the laws governing the privacy of individual data in Switzerland.

FINMA Circular 2018/3

Circular 2018/3 of the Swiss Financial Market Supervisory Authority (FINMA) describes the conditions under which outsourcing solutions are compliant with requirements for appropriate service providers, banking secrecy and data protection. The official FINMA Circular can be downloaded here as a pdf file.

BAFIN / BAIT: Circular 10/2017 (BA)

Circular 10/2017 (BA) of BAFIN, the German financial markets regulator describes the supervisory requirements for IT in financial institutions. Safe Swiss Cloud is compliant with these requirements.

DORA

The DORA Regulation (Digital Operational Resilience Act) is an EU-wide regulation to strengthen digital operational resilience in the financial sector, which has been mandatory since 17 January 2025. It requires financial institutions and their ICT third-party service providers to meet uniform standards for ICT risk management, incident reporting, and the resilience of critical IT systems.

FMH Recommendations for doctors

The FMH is Switzerland’s professional association for doctors. The FMH has published details of what doctors, medical practitioners and healthcare services have to consider in order to be compliant with the Swiss DPA (German only).

Safe Swiss Cloud meets these requirements.

HIPAA

The Health Insurance Portability and Accountability Act (HIPAA) sets the standard for sensitive patient data protection. Companies that deal with protected health information (PHI) must have physical, network, and process security measures in place and follow them to ensure HIPAA Compliance.

GxP

Quality standards and guidelines applied in the pharmaceutical, biotechnology and food industries, but also in other regulated industries such as medical technology and the cosmetics industry.

C5

Germany’s leading standard for testing and certifying the security of cloud services, developed by the Federal Office for Information Security (BSI). The C5 catalog covers all core areas of cloud security – organizational, technical and procedural controls – and includes topics such as data protection, physical security, governance and incident management

NIS2

The NIS2 Directive is an EU-wide regulation to strengthen the cybersecurity and resilience of network and information systems, which has been in force since the 17th century. October 2024 is valid. It extends the scope of the previous NIS Directive to a wider range of sectors in the private and public sectors.

Applicable laws


Customer data hosted with Safe Swiss Cloud is subject exclusively to Swiss law. Three layers apply in parallel: data protection legislation for personal data, statutory secrecy obligations for business-related data, and the European framework that recognises Switzerland as a safe destination for personal data transfers.

Swiss data protection law

The Federal Act on Data Protection (FADP, SR 235.1), in force in its revised form since 1 September 2023, and the Data Protection Ordinance (DPO, SR 235.11) govern the processing of personal data in Switzerland. Safe Swiss Cloud’s computing resources and the data stored on them are accessible only to the customer and to parties explicitly authorised by the customer.

Statutory secrecy obligations

Business-related customer data are protected by separate confidentiality provisions. Safe Swiss Cloud acknowledges that customer data may be subject to official secrecy (Art. 320 Swiss Criminal Code, StGB), professional secrecy (Art. 321 et seq. StGB), banking secrecy (Art. 47 Banking Act, BankG), manufacturing and business secrecy (Art. 162 StGB) or the professional confidentiality obligation under Art. 62 FADP. These duties are contractually acknowledged and passed on to all personnel with access to customer systems.

EU adequacy

Commission Decision 2000/518/EC (OJ L 215, 25.8.2000, p. 1) recognises Switzerland as providing an adequate level of protection for personal data transferred from the EU. The decision remains in force under Art. 45(9) GDPR, and the European Commission confirmed its continued validity in its review report of 15 January 2024. Transfers from the EU and EEA to Safe Swiss Cloud therefore require no standard contractual clauses or additional safeguards.

Swiss jurisdiction

Data remain under Swiss jurisdiction at all times. Requests from foreign authorities can only be processed through Swiss mutual legal assistance procedures; acting directly on behalf of a foreign state on Swiss territory is prohibited under Art. 271 StGB. As a Swiss company operating exclusively from Swiss data centres, Safe Swiss Cloud is outside the reach of the US CLOUD Act and comparable extraterritorial access regimes

FAQ


Frequently Asked Questions

How is Security Implemented at Safe Swiss Cloud?

Safe Swiss Cloud takes many steps to ensure the security of our customer’s data and computing resources:

  • Keep the operating systems on the all the hosts of our cloud systems up to date.
  • Two factor authentication TFA for access to cloud management systems.
  • Keeping the cloud systems up to date.
  • Physical security at the data centres.
  • Regular network scans to detect irregularities.
  • Regular employee security training.
  • Regular reviews of access rights.

In addition, customers who delegate (parts of) their IT Operations to Safe Swiss Cloud benefit from the following:

  • Anti-Malware installed on the customer’s servers.
  • Security Operations Center (SOC): monitoring with daily review of security events.
  • Regular backups to separate, independent systems which are out of reach for Ransomware.
  • Managed firewalls.
  • Penetration tests and vulnerability scans.
  • Two factor authentication TFA for access to customer’s servers (VMs).
  • Regular security updates (“patching”) of customer servers (VMs).
  • Proactive customer confirmation of allowed users.

The above and our internal security processes are documented according to ISO 27001, 27017, 27018. They are audited and certified annually.

Which data centres do you use?

All computing resources and data are in Safe Swiss Cloud’s own world class data centers in Switzerland. In the heart of Europe, Switzerland is politically and geographically one of the most stable countries in the world.

Our processes and data centers have the appropriate certifications required for the compliance of businesses large and small.

Safe Swiss Cloud is a great choice for European companies and organisations who want to ensure compliance with EU data protection / GDPR.

What can you tell us about your data center?
We use the Interxion data center in Glattbrugg, near Zürich. This facility meets the requirements of the Swiss financial regulator FINMA – see the following KPMG document for the details: FINMA-RS 08/7: Outsourcing – banks
Which laws apply to Safe Swiss Cloud infrastructure and hosting?

Respect for the privacy of individual and company data is required by Swiss law: SR 235.1 Federal Act on Data Protection. Safe Swiss Cloud computing resources and data are accordingly only accessible to our client or parties authorized by them.

Safe Swiss Cloud is compliant with the European Union’s (EU) comprehensive data protection laws, GDPR. For more details about European Union’s GDPR, visit this European Commission page.

As a 100% Swiss owned company, Safe Swiss Cloud is bound only by Swiss, European and accepted International legal practice.

The European Union (EU) considers Swiss data protection to be adequate to allow individuals and businesses in the EU to use Swiss based data processing. This makes Safe Swiss Cloud a good choice for EU companies who want to ensure compliance with the EU’s GDPR data protection directives.