A European data centre is a change of address, not a change of jurisdiction
Under the US CLOUD Act an American court can compel any US provider to hand over data, wherever the servers stand. Choosing that vendor's Frankfurt region does not change who can be served. It changes where the disks are. SANDSIV is Swiss. There is no US entity to serve.
The company
- SandSIV Schweiz AG, Technoparkstrasse 1, 8005 Zurich.
- Registered in the Commercial Register of the Canton of Zurich, UID CHE-348.804.240. Verifiable in the public register in about a minute.
- No US parent. No US investors. None in the UK holding either.
The infrastructure
- Hosted on Exoscale, operated by Akenes SA, a Swiss company founded in 2011.
- Exoscale's parent is A1 Digital, part of the Austrian A1 Telekom Austria Group. Austrian, not American. No US entity anywhere in that chain.
- Eight zones, five countries, all Swiss or EU: Geneva, Zurich, Vienna (two), Frankfurt, Munich, Sofia, Zagreb.
- You can pin the country by contract. Switzerland only is a real option, not a marketing region label.
- Exoscale certifications: ISO/IEC 27001:2022, 27017, 27018, SOC 2, CSA STAR, TISAX, BSI C5, HDS, GDPR, Swiss FDPA.
Four ways to run it
| Model | Where the platform runs | Where the model runs | Who operates it |
|---|---|---|---|
| EU or Swiss cloud | Exoscale, zone you pin | See AI below | Us |
| Private cloud | Dedicated tenancy | Private cloud inference available | Us |
| Your data centre | Your infrastructure | Your infrastructure | You, with us |
| Fully on premise | Inside your walls | Inside your walls | You |
Same product in all four. What changes is where it runs and who holds the keys. Updates to an air gapped install are delivered through your service provider. No inbound connection from us is required.
AI, which is the question that actually gets asked
The question a model risk committee asks is not where data is stored. It is where it is processed at inference time.
- You choose whether your data leaves the EU. It is a configuration, not a support ticket.
- Open weight models are computed in the EU.
- Enterprise customers can have inference on premise or in a private cloud, with the model inside their own perimeter.
- Nothing you put in ever trains a shared model. There is no cross customer training corpus.
What you can hold us to
- Data residency in the zone you pin. We do not move data between regions to balance load or to run analysis.
- No transfer outside Switzerland, the UK and the EEA without the safeguards the data protection law requires. That is the standing commitment in our privacy notice, not a sentence written for this page.
- Customer managed keys. BYOK is supported.
- Penetration testing is a normal part of onboarding. Bring your tester.
- Full export, open architecture, no lock in. Including on the way out.
- Certifications: ISO 27001, 27701, 27017 and 27018, SOC 2 Type II, CSA STAR Level 1. The scope statements cover the platform, not just the corporate office. Ask for them.
Who runs it this way
Kantonsspital Winterthur runs sandsiv+ with Swiss patient data, in one of the most tightly regulated data categories in the country. Swisscom is a customer. Both are quoted by name on our homepage, by a named individual.
The warning
Most of the large Voice of the Customer platforms are American companies. Several will offer you an EU region, and some will offer a sovereign tier. Read what that actually gives you.
- The CLOUD Act reaches the company, not the building. A US provider with a Frankfurt region is still a US provider. The order is served in America.
- The Swiss and EU-US Data Privacy Frameworks are adequacy decisions, not immunity. They govern how data may be transferred. They do not remove a US court's reach over a US company, and adequacy decisions have been struck down twice before.
- Encryption does not solve it if the provider holds the keys. Ask who can decrypt, and ask it in writing.
- The stack is longer than the database. Hosting is one answer. The CDN, the object store, the monitoring, the email, and above all the model endpoint each have their own jurisdiction. A vendor that answers only about hosting has answered the easy third of the question.
If you are on Medallia or Qualtrics and this matters to you, the comparison pages set out what switching actually costs and how the migration runs.
What we do not claim
A sovereignty page that only says yes is not worth reading.
- We are not a sovereign cloud provider. In the cloud models we run on infrastructure a third party operates, in the country you pick. If your requirement is that no third party operator exists anywhere in the stack, on premise is the only model that satisfies it, and we will tell you that rather than sell you a public deployment.
- Swiss incorporation is not immunity. Switzerland has its own legal process for compelled disclosure. The claim is narrower and harder: the CLOUD Act specifically cannot reach us, because there is no US entity to serve.
- This website is not the platform. The marketing site you are reading uses American services, disclosed in our privacy notice. Your customer feedback would not live here. We would rather point at that ourselves than have you find it.
- Certifications are not a security guarantee. They show a control framework exists and was tested. Your configuration is what the penetration test is for.
- On premise costs more and moves slower. Upgrades follow your change windows, not ours. Choose it because you need it.
Bring your security questionnaire to the first call. You will get written answers, not a datasheet.
Book a demo