Swiss data residency ISO 27001 Swiss nFADP GDPR

AI models you can actually put regulated data through.

One OpenAI-compatible endpoint. Every model carries a machine-readable compliance record — where it runs, who can legally compel access to it, whether anything is retained, and which data classes it is fit for. Filter by your obligations, not by marketing claims.

Browse the model catalog Read the compliance guide
5
residency levels, scored 1–5
0
prompts retained by Swiss-hosted options
5
compliance questions answered per model
Highest sovereignty first

Compliant models

Certifications shown are those held by the operator running the model.

Llama 3.3 70B

Open weights

Runs on your own hardware

Qwen3.5 397B A17B FP8

Open weights

Swiss data residencyISO 27001Swiss nFADPGDPR

Kimi K2.6

Open weights

Swiss data residencyISO 27001Swiss nFADPGDPR

Qwen3.5 122B A10B FP8

Open weights

Swiss data residencyISO 27001Swiss nFADPGDPR

Mistral Small 4 119B

Open weights

Swiss data residencyISO 27001Swiss nFADPGDPR

Gemma 4 31B Instruct

Open weights

Swiss data residencyISO 27001Swiss nFADPGDPR
See every model and filter them →
The ground rules

Why this matters when a company uses AI

Sending a prompt to a model is a data transfer. If that prompt contains personal data, client data or a trade secret, every rule that normally governs outsourcing and cross-border transfer applies to it — and most AI APIs are, legally speaking, a transfer to a foreign processor.

Swiss nFADP / revDSG

Switzerland's revised Federal Act on Data Protection, in force since September 2023. It requires a lawful basis for processing, a written agreement with any processor you use, and a record of processing activities. Transfers abroad are only allowed to countries the Federal Council recognises as adequate, or under safeguards such as standard contractual clauses. Sensitive personal data — health, religion, trade union membership, biometrics, criminal proceedings — carries stricter duties. Breaches must be reported to the FDPIC, and certain violations are criminal offences for the responsible individual, not just the company.

GDPR

Applies whenever you process the personal data of people in the EU/EEA, regardless of where your company sits. It brings the same core duties as nFADP plus data subject rights, DPIAs for high-risk processing, and Chapter V rules on international transfer. Fines reach 4% of global annual turnover. Most Swiss companies with EU customers or staff are subject to both regimes at once.

ISO 27001

A certification of the provider's information security management system, audited by an accredited third party. It tells you the operator has documented controls for access, encryption, incident response and supplier management, and that someone independent checked. It is evidence of diligence in your own supplier assessment — but note it says nothing about where data sits or who can compel access.

Data residency and the CLOUD Act

Residency is the physical location of processing. Jurisdiction is which government can compel disclosure — and the two are not the same. Under the US CLOUD Act, a US-incorporated provider can be ordered to produce data it controls even when that data sits in a Zurich or Frankfurt data centre. This is why a "Swiss region" from a US hyperscaler is not equivalent to a Swiss company operating its own infrastructure.

Know your bar

Different obligations need different models

There is no single "compliant" answer. What you must insist on depends on your regulator, the data class, and how bad a compelled disclosure would be. A rough ladder:

5

Your own hardware

Professional secrecy under Art. 321 SCC (lawyers, doctors, clergy), patient records, unreleased financial results, M&A material. Nothing leaves your premises, so there is no processor to contract with and no foreign authority to serve an order on.

4

Swiss operator, Swiss infrastructure, no foreign parent

FINMA-regulated banks and insurers under Circular 2018/3, health data, employee files, client identifying data. A Swiss company running its own data centres is subject only to Swiss law, so there is no CLOUD Act exposure to disclose in an outsourcing notification.

3

Swiss region, foreign parent

Listed companies and general corporate use where data stays in Switzerland but the operator is a US or other foreign group. Residency is satisfied; jurisdiction is not. Usually acceptable for internal and confidential data, rarely for regulated secrecy.

2

EU/EEA residency

GDPR-adequate and often enough for EU personal data, marketing, and general business content. Note Switzerland is not in the EU: an EU host does not satisfy a Swiss-residency requirement, and a Swiss host does not by itself satisfy an EU-processing requirement.

1

Outside Switzerland and the EU

Public and non-sensitive content only — published material, synthetic data, open-source code, throwaway drafts. Assume a foreign authority could compel access and that the prompt may be retained for abuse monitoring.

Retention and training

Zero retention means the prompt is not stored after the response. Some providers still keep 30 days for abuse monitoring, which is a disclosable sub-processing step. "No training on customer data" is a separate promise again — check both.

Open vs closed weights

Open weights can be self-hosted, audited, and pinned to a version that will not change under you. That makes reproducibility and exit strategy realistic. Closed weights mean you depend on one vendor's continued availability and terms.

Local vs cloud

Local gives absolute control and no per-token cost, at the price of capability and uptime you must run yourself. Swiss cloud gives frontier-class quality with a contractual guarantee instead of a physical one.

Full guide: which model for which obligation →

Pick by obligation, not by benchmark

The catalog filters map one-to-one onto the concepts above — residency level, sovereignty score, CLOUD Act exposure, training, DPA, data class. The guide explains how to set them for your company type.

Open the catalog Read the guide