Security & Swiss Data Residency

Security and data sovereignty are architecture at Leistera, not marketing rhetoric. Application databases, customer documents, and backups remain in Switzerland. Models are never trained on your project files or proposals.

Last updated: 16. August 2026·Zürich, Schweiz·100% nDSG & GDPR compliant

Zero Migration

Files remain in your Microsoft SharePoint. Strictly read-only Graph API access.

Zero Model Training

Your bids and project archives are contractually guaranteed never to be trained on.

Swiss Data Residency

Databases, metadata, and backups reside strictly in Swiss data centres.

Swiss DPA Contract

Binding Data Processing Agreement under Swiss FADP with jurisdiction in Zurich.

Data Residency & Control Matrix

Transparent breakdown of storage locations, inference endpoints, and legal guarantees.

CONTRACTUALLY BOUND
Swipe table horizontally4 columns
ComponentStandard TierSwiss Inference TierArchitecture & Proof
Customer Files & DrawingsRemain in your Microsoft 365 / SharePointUnchanged in your tenant (CH / EEA)Read-only access via Microsoft Graph. Zero migration, zero duplicate storage.
Application Database & IndexSwitzerland (Infomaniak Zurich / Geneva)Switzerland (Azure Switzerland North)Strict tenant isolation at database level with Row-Level Security (RLS) and signed tenant tokens.
Backups & ArchivalSwitzerland (encrypted, AES-256)Switzerland (Geo-redundant CH)Fully encrypted snapshots inside Swiss data centres with 30-day retention.
Model Inference & LLMsContractually bound endpoints (EEA / CH)100% Swiss Inference (Azure Switzerland North)Zero Data Retention (ZDR) agreement. Prompts and context are discarded immediately after inference.
Model Training on Customer DataStrictly excludedStrictly excludedContractually guaranteed in the Data Processing Agreement (DPA). Your proposals remain your IP.
Public Swiss Norms & CodesSwiss Repository (SIA, ASTRA, VSS, TBA)Swiss Repository (SIA, ASTRA, VSS, TBA)Valid editions with cut-off verification, chapter, and page citations. Fully isolated from client IP.

1. Swiss Data Protection (FADP/nDSG) & GDPR

Leistera fully complies with the revised Swiss Federal Act on Data Protection (FADP/nDSG) and the European General Data Protection Regulation (GDPR).

We execute a formal Data Processing Agreement (DPA) under Swiss law with every client. Jurisdiction is Zurich, Switzerland.

Personal data (such as engineer CVs or project staff credentials) is processed strictly for proposal compilation and never disclosed to unauthorized third parties.

2. Microsoft Graph & Zero-Migration Architecture

Zero data migration: Leistera does not require moving CAD drawings, specifications, or archives into a separate cloud silo. Your files remain securely in your Microsoft SharePoint and OneDrive.

Strictly read-only: Integration is established via the official OAuth2-authenticated Microsoft Graph API with read-only permissions. Leistera cannot modify, overwrite, or delete any source files.

Permission inheritance: Query inference respects your active Microsoft Entra ID (Azure AD) access rights. Users only receive citations from documents they are authorized to view.

3. Tenant Isolation & Encryption

Logical isolation: Every client operates in a strictly isolated tenant scope. Database queries are enforced via cryptographically signed tenant tokens and PostgreSQL Row-Level Security (RLS).

Encryption at rest: All stored index vectors and metadata are encrypted with industry-standard AES-256.

Encryption in transit: All network traffic between browser, backend, and APIs is encrypted using TLS 1.3 with HSTS and rigorous Content Security Policies (CSP).

4. Human-in-the-Loop & Professional Liability

Partner signature remains mandatory: Leistera creates structured, grounded drafts with exact document, edition, and page citations. The platform never makes autonomous submissions.

Professional engineering duty of care: Lead engineers and architects inspect every draft against linked original pages before submitting on SIMAP or to clients.

Radical transparency: If a tender requirement cannot be verified against your archive or public codes, Leistera explicitly flags 'not found' rather than hallucinating plausible claims.

Custom Security Review & IT Questionnaire

We complete your internal IT security and data privacy questionnaires within 48 hours and present architecture details before initiating any pilot.

Request Security Dossier
Security & Swiss Data Residency | Leistera