SECURITY OF OUR INFRASTRUCTURE

(September 2026 edition)

Our platforms, our clients' data and our backups are hosted on Swiss infrastructure, operated by a Swiss company, under Swiss law.

Many of our clients are banks, securities firms, asset managers and other financial intermediaries, for whom engaging a supplier is a decision subject to internal review. This page sets out where our platforms run, who operates that infrastructure, which certifications that operator holds, and how access to your data is protected.

In brief
  • All of our platforms, the data our clients entrust to us and our backups are hosted in data centres in Geneva, Switzerland.
  • Our hosting partner is Infomaniak Network SA, a Swiss company that owns and operates its own data centres and holds ISO 27001, ISO 9001, ISO 14001 and ISO 50001 certification.
  • Your data is processed and stored in Switzerland, and is not hosted by a provider subject to foreign jurisdiction.
  • Card payments are the single deliberate exception, handled by a specialised certified payment provider so that no card details ever reach our systems.

WHERE THE SERVERS PHYSICALLY ARE

Our infrastructure runs on the public cloud of Infomaniak Network SA, Switzerland's leading independent hosting provider, in its own data centres in the canton of Geneva.

Three characteristics matter for a supplier assessment:

  • Swiss ownership and operation. Infomaniak is an independent Swiss company with no foreign parent. It designs, builds and runs its own data centres rather than reselling capacity from a larger provider, and it does not outsource its operations or its support.
  • Tier III+ facilities. The data centres are built to a Tier III+ standard with n+1 redundancy on power supply, cooling, generators and uninterruptible power. Physical access passes through several security airlocks and a facial recognition system, and the precise location of the buildings is not published.
  • Swiss jurisdiction. Because both the company and the hardware are in Switzerland, the data is governed by Swiss law. Infomaniak's stated position is that no authority can obtain access to personal data without the approval of a judge.

The facilities are also unusually efficient: cooled without air conditioning, powered entirely by renewable Swiss energy, and recovering server heat into Geneva's district heating network. That is not a security property, but it is often relevant to the environmental section of the same questionnaire.

CERTIFICATIONS HELD BY OUR HOSTING PARTNER

These certifications are audited by independent third parties and renewed periodically. The certificates are published and can be downloaded directly from Infomaniak.

ISO 27001:2022Information security. Requirements for an information security management system. Held since June 2018.
ISO 9001:2015Quality management. Framework for consistent service delivery and customer satisfaction. Held since July 2022.
ISO 14001:2015Environmental management. Measuring and reducing environmental impact. Held since April 2015.
ISO 50001:2018Energy management. Measurable energy performance targets and continuous improvement. Held since April 2015.
Swiss HostingData residency label. Certifies that the provider is legally and physically located in Switzerland and that customer data is hosted and executed in a Swiss data centre.
Swiss Made SoftwareDevelopment origin. Certifies that development takes place in Switzerland. Infomaniak develops its solutions exclusively in Switzerland.
B Corp™Social and environmental governance. Certified since 2025.

VisionCompliance SA is not itself ISO 27001 certified. The certifications above belong to the provider that hosts our infrastructure. What we bring is the choice of that provider, the way we have configured the platform, and the internal measures described below.

WHERE YOUR DATA IS

Everything we operate is hosted in Switzerland by Infomaniak: our websites and applications, the databases behind them, the files our applications store, our backups, our service emails and, where our sites provide one, the AI assistant.

Accounting and invoicing data is kept in bexio, a Swiss business management solution whose servers are likewise located in Switzerland, in a data centre certified to ISO 27001.

There is one deliberate exception. Card payments are handled by Stripe, which operates outside Switzerland.

On the payment exception

Card payments are processed by Stripe, certified at PCI DSS Level 1, the highest level of the card industry's security standard. Card numbers are entered directly into Stripe's own secure fields and are never transmitted to, processed by or stored on our servers. We receive only the confirmation that a payment succeeded, together with the billing details needed to issue an invoice.

On website analytics

We do not use Google Analytics or any comparable third-party tracking service. We do not profile visitors, we do not process behavioural data, and we do not sell personal data.

HOW ACCESS TO YOUR DATA IS PROTECTED

Hosting location answers only one half of a supplier review. The other half is how the platform itself is protected.

Encryption

All traffic between your browser and our platforms is encrypted in transit using TLS. At rest, the data is held on our hosting provider's encrypted infrastructure in Switzerland: the volumes carrying the database are encrypted at disk level and replicated three times within the Swiss cluster, and the object storage holding documents and backups applies encryption at the storage layer.

Authentication

Accounts can be secured with passkeys, a passwordless method using the fingerprint, face or PIN of the user's own device, which cannot be phished or reused, and with two-factor authentication by authenticator app. Passwords, where used, are stored only as irreversible cryptographic hashes.

Least privilege

Administrative functions are separated from ordinary user accounts and restricted to a small number of named individuals. Access to the underlying servers is limited to authenticated key-based connections from a restricted set of administrators.

Resilience

The database is backed up automatically every night at 03:00. Each backup is written to a private area of our Swiss object storage, separate from the running system and not publicly reachable: it can be retrieved only by an authenticated administrator, through a link that expires. Backups are removed by an automated cleanup process and are held for no longer than 90 days.

Sensitive operations are rate-limited to blunt automated abuse.

Data minimisation

We collect only what the service requires. We do not process sensitive, behavioural, biometric or preference data, we do not carry out profiling, and we take no automated individual decisions. Retention periods are set out in our Personal Data Protection Statement.

THE REGULATORY PICTURE

For clients who are themselves supervised institutions, the provisions that usually arise in a supplier review are the following.

FINMA Circular 2018/3 — Outsourcing (banks and insurers)

Supervised institutions must be able to identify where outsourced data resides, retain access and audit rights, and assess the provider's security. This page, our Personal Data Protection Statement and our contractual documents are intended to support that assessment. Institution-specific outsourcing annexes can be agreed on request.

Federal Act on Data Protection (nFADP), in force since 1 September 2023

We process personal data under the revised Swiss data protection regime, including its requirements on data security, records of processing and transparency towards data subjects.

GDPR — for clients and staff in the European Union

Switzerland benefits from a European Commission adequacy decision, so personal data may be transferred from the EU and EEA to Switzerland without additional safeguards such as standard contractual clauses.

US CLOUD Act

Our hosting provider is a Swiss company with no United States parent or subsidiary, and our data is not held by a provider subject to US jurisdiction.

This page is provided for information purposes to assist clients in their supplier assessments. It describes our infrastructure as at the edition date shown above and does not, on its own, constitute a contractual commitment. The certifications described above are held by Infomaniak Network SA and are subject to that company's own audit and renewal cycles. Our contractual terms and our Personal Data Protection Statement prevail in the event of any inconsistency.