Your data deserves the highest protection
RechtsKI was built from the ground up for the Swiss legal market — with data protection as a core principle, not an afterthought.
How your data flows
Every connection is encrypted. Customer data is stored exclusively in Switzerland with Safe Swiss Cloud; AI requests are processed by default via Microsoft Azure in the Switzerland North region (geographically Switzerland) and can be routed entirely via Safe Swiss Cloud on a per-request basis.
- RechtsKI Backend: CORS · Auth · RBAC
- Azure OpenAI: Switzerland North
- Safe Swiss Cloud: Storage · Switzerland
- Firebase: AES-256 · HKDF
- Data flow architecture — All connections TLS 1.2+ encrypted
Our security concept
Encryption, Swiss AI processing and ephemeral sessions form the foundation of our data protection.
AES-256-GCM Encryption
Per-user keys via HKDF (SHA-256)
- Conversation histories are encrypted before storage — only you can decrypt them.
- Per-User Key Derivation — each user receives an individual key derived via HKDF.
- Documents & Uploads are encrypted and deleted after processing.
Azure OpenAI — Switzerland
Microsoft Azure DPA · Region Switzerland North
- Region Switzerland North — inference and data residency per Azure region in Switzerland. Contractual commitments (DPA) and configured retention settings apply.
- No model training — per Azure OpenAI contractual terms, customer data is not used to train models.
- Abuse monitoring temporary (max. 30 days), then complete deletion.
Ephemeral AI Sessions
Triple-secured: End-Session · Cleanup · Delete
- Automatic deletion — every AI session is immediately deleted after completion.
- Encrypted copy — your history remains only in your personal storage, AES-256-GCM encrypted.
- Proactive cleanup — multiple security layers ensure no orphaned sessions remain.
nDSG Compliance in Detail
The revised Swiss Data Protection Act (nDSG), effective since September 1, 2023, sets high requirements. Here's how we implement them.
Data processing in Switzerland
Customer data is stored exclusively in Switzerland with Safe Swiss Cloud. AI requests are processed by default via Microsoft Azure in the Switzerland North region and can be routed entirely via Safe Swiss Cloud on a per-request basis. For certain infrastructure services (e.g. authentication), technical metadata may be processed outside Switzerland per provider setup; we minimise this and transparently document all sub-processors.
AES-256-GCM with per-user keys
Each user receives their own encryption key, derived via HKDF. Even in case of a database leak, your content remains protected.
No AI training with your data
Per Azure OpenAI contractual terms, customer data is not used to train models. Your client data remains your client data.
Ephemeral AI sessions
After each session, AI conversations are automatically deleted. Only the encrypted copy in your personal storage is retained.
Data minimization (Privacy by Design)
We only collect data necessary for operation. Documents are deleted after processing, temporary data is not persisted.
Transparency & data subject rights
You have the right to information, rectification, deletion and data portability at any time pursuant to Art. 25–29 nDSG. Contact us for any request.
Data processing agreements per Art. 9 nDSG
Our data processing agreements with Safe Swiss Cloud, Microsoft Azure and Google Firebase comply with the requirements of the revised Data Protection Act.
Encryption in transit & at rest
TLS 1.2+ for all connections. AES-256-GCM for stored data. Keys are derived via HKDF with SHA-256 from a master key — never stored in plaintext.
What we do
- Store all customer data exclusively in Switzerland with Safe Swiss Cloud
- Encrypt all data with AES-256-GCM and individual keys
- AI processing in Switzerland (Azure Region Switzerland North) per DPA
- Automatically delete AI sessions after each session with multiple safeguards
- Data processing agreements with all service providers
- Transparent privacy policy according to nDSG
What we don't do
- Use your data for AI training
- Sell or share data with third parties
- Conduct primary data processing outside of Switzerland
- Store unencrypted personal data
- Conduct tracking or profiling for advertising purposes
- Keep AI sessions longer than necessary
- Allow access without authentication
Enterprise infrastructure — Swiss data location
Microsoft Azure
- Region Switzerland North – Data processing in Switzerland
- Azure OpenAI – Data Processing Agreement
- No model training with customer data
Safe Swiss Cloud
- Storage of customer data exclusively in Switzerland — ISO 27001-certified Swiss provider.
- Swiss LLM mode — AI processing can be routed entirely via Safe Swiss Cloud on a per-request basis; as a non-US company, Safe Swiss Cloud is not subject to the US CLOUD Act.
- OCR and anonymisation are processed via Safe Swiss Cloud as a matter of principle.
Google Firebase
- AES-256-GCM with per-user HKDF key derivation
- Token-based authentication with Firebase Auth
- Data processing per Swiss/EU data protection law
Full Privacy Policy
All legal details, data subject rights and data processing information can be found in our full privacy policy.