Security & Swiss Data Residency
Security and data sovereignty are architecture at Leistera, not marketing rhetoric. Application databases, customer documents, and backups remain in Switzerland. Models are never trained on your project files or proposals.
Zero Migration
Files remain in your Microsoft SharePoint. Strictly read-only Graph API access.
Zero Model Training
Your bids and project archives are contractually guaranteed never to be trained on.
Swiss Data Residency
Databases, metadata, and backups reside strictly in Swiss data centres.
Swiss DPA Contract
Binding Data Processing Agreement under Swiss FADP with jurisdiction in Zurich.
Data Residency & Control Matrix
Transparent breakdown of storage locations, inference endpoints, and legal guarantees.
| Component | Standard Tier | Swiss Inference Tier | Architecture & Proof |
|---|---|---|---|
| Customer Files & Drawings | Remain in your Microsoft 365 / SharePoint | Unchanged in your tenant (CH / EEA) | Read-only access via Microsoft Graph. Zero migration, zero duplicate storage. |
| Application Database & Index | Switzerland (Infomaniak Zurich / Geneva) | Switzerland (Azure Switzerland North) | Strict tenant isolation at database level with Row-Level Security (RLS) and signed tenant tokens. |
| Backups & Archival | Switzerland (encrypted, AES-256) | Switzerland (Geo-redundant CH) | Fully encrypted snapshots inside Swiss data centres with 30-day retention. |
| Model Inference & LLMs | Contractually bound endpoints (EEA / CH) | 100% Swiss Inference (Azure Switzerland North) | Zero Data Retention (ZDR) agreement. Prompts and context are discarded immediately after inference. |
| Model Training on Customer Data | Strictly excluded | Strictly excluded | Contractually guaranteed in the Data Processing Agreement (DPA). Your proposals remain your IP. |
| Public Swiss Norms & Codes | Swiss Repository (SIA, ASTRA, VSS, TBA) | Swiss Repository (SIA, ASTRA, VSS, TBA) | Valid editions with cut-off verification, chapter, and page citations. Fully isolated from client IP. |
1. Swiss Data Protection (FADP/nDSG) & GDPR
Leistera fully complies with the revised Swiss Federal Act on Data Protection (FADP/nDSG) and the European General Data Protection Regulation (GDPR).
We execute a formal Data Processing Agreement (DPA) under Swiss law with every client. Jurisdiction is Zurich, Switzerland.
Personal data (such as engineer CVs or project staff credentials) is processed strictly for proposal compilation and never disclosed to unauthorized third parties.
2. Microsoft Graph & Zero-Migration Architecture
Zero data migration: Leistera does not require moving CAD drawings, specifications, or archives into a separate cloud silo. Your files remain securely in your Microsoft SharePoint and OneDrive.
Strictly read-only: Integration is established via the official OAuth2-authenticated Microsoft Graph API with read-only permissions. Leistera cannot modify, overwrite, or delete any source files.
Permission inheritance: Query inference respects your active Microsoft Entra ID (Azure AD) access rights. Users only receive citations from documents they are authorized to view.
3. Tenant Isolation & Encryption
Logical isolation: Every client operates in a strictly isolated tenant scope. Database queries are enforced via cryptographically signed tenant tokens and PostgreSQL Row-Level Security (RLS).
Encryption at rest: All stored index vectors and metadata are encrypted with industry-standard AES-256.
Encryption in transit: All network traffic between browser, backend, and APIs is encrypted using TLS 1.3 with HSTS and rigorous Content Security Policies (CSP).
4. Human-in-the-Loop & Professional Liability
Partner signature remains mandatory: Leistera creates structured, grounded drafts with exact document, edition, and page citations. The platform never makes autonomous submissions.
Professional engineering duty of care: Lead engineers and architects inspect every draft against linked original pages before submitting on SIMAP or to clients.
Radical transparency: If a tender requirement cannot be verified against your archive or public codes, Leistera explicitly flags 'not found' rather than hallucinating plausible claims.
Custom Security Review & IT Questionnaire
We complete your internal IT security and data privacy questionnaires within 48 hours and present architecture details before initiating any pilot.