# Your developer platform, your data, your jurisdiction

When a regulated organization runs its developer platform on a US hyperscaler, every pipeline run, secret, audit log, and code artifact falls under the [CLOUD Act](https://en.wikipedia.org/wiki/CLOUD_Act). US authorities can compel access without Swiss judicial process, regardless of the region selected. For organizations in Swiss finance, healthcare, and government, this is not a theoretical risk: it is a compliance gap that due diligence reviews are catching.

VSHN operates your internal developer platform on Swiss infrastructure: Swiss company, Swiss staff, Swiss law. Your data stays in Switzerland.

## Why VSHN-operated platforms strengthen your sovereignty

- **Swiss company, Swiss law**: VSHN AG is incorporated in Switzerland. No foreign parent, no CLOUD Act exposure
- **Open-source stack, no vendor lock-in**: GitLab, Crossplane, OpenTofu, and OpenBao are community-governed open-source projects. No hyperscaler proprietary APIs in the critical path
- **ISO 27001 certified**: Since 2014, with ISAE 3402 Type II attestation covering the operational controls that protect your platform
- **GitOps audit trail**: Every change to your platform configuration goes through Git. Full audit history of who changed what and when, suitable for regulatory inspection
- **Cloud choice**: Run on Cloudscale, Exoscale, or your own Azure tenant in Switzerland. You decide where compute and storage run
- **Swiss operations team**: All on-call engineers are based in Switzerland. [Swiss-only support option](https://products.vshn.ch/support_plans.html#_option_switzerland_only_support) available for regulated requirements

## Sovereignty compared

| Dimension | DIY (self-operated) | Hyperscaler managed | VSHN-operated |
|-----------|---------------------|--------------------|-----------------------|
| **Governing law** | Your jurisdiction | US law | Swiss law |
| **CLOUD Act** | Not exposed | Exposed | Not exposed |
| **Data location** | Your choice | Configurable (US-controlled) | Switzerland or customer DC |
| **Operations team** | Your hires (4-6 FTE min) | Vendor staff | Swiss-based VSHN engineers |
| **Audit trail** | You build it | Vendor logs (limited access) | GitOps history, full export |
| **Vendor independence** | Full | Proprietary APIs | Open-source, portable |
| **Compliance evidence** | Build from scratch | Vendor shared-responsibility | ISO 27001, ISAE 3402, named references |

## Compliance and regulatory readiness

VSHN-operated developer platforms support your organization's compliance requirements:

- **FINMA Circular 2018/3**: Outsourcing requirements for Swiss financial institutions. VSHN provides audit documentation, Swiss-only operations, and contractual commitments for regulated customers
- **EU DORA** (Digital Operational Resilience Act): ICT third-party risk management provisions. Swiss-hosted operations with documented SLAs meet DORA's requirements for critical ICT service providers
- **NIS2 Directive**: Supply chain security requirements for essential and important entities. VSHN's ISO 27001 controls map to NIS2 Article 21 requirements
- **GDPR / Swiss DPA**: Swiss data residency by default. EU adequacy decision covers Swiss-EU data transfers

## VSHN sovereignty self-assessment

We applied the EU's [Cloud Sovereignty Framework](https://commission.europa.eu/document/09579818-64a6-4dd5-9577-446ab6219113_en) (v1.2.1, October 2025) to our own services. This framework was used to score providers in the EU's [EUR 180M sovereign cloud tender](https://ec.europa.eu/commission/presscorner/detail/en/ip_26_833) in April 2026. Three pure-European providers achieved SEAL-3, while a consortium involving Google Cloud scored only SEAL-2.

*This is a self-assessment, not a formal SEAL certification. We publish it for transparency so customers can evaluate our sovereignty profile using the same structured criteria the EU uses.*

| # | Dimension | Weight | Assessment | Evidence |
|---|-----------|--------|-----------|----------|
| SOV-1 | Strategic | 15% | **Strong** | Swiss AG, no foreign parent, all shareholders Swiss citizens ([Commercial Register](https://zh.chregister.ch/cr-portal/auszug/auszug.xhtml?uid=CHE-275.566.226)) |
| SOV-2 | Legal | 10% | **Strong** | Swiss law ([GTC](https://products.vshn.ch/legal/gtc_en.html)), no CLOUD Act, [EU adequacy decision](https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en) |
| SOV-3 | Data & AI | 10% | **Strong** | Swiss DCs by default. Sovereign key management via [Managed OpenBao](https://www.openbao.ch) + [Swiss HSM](https://cloud.securosys.com/cloudhsm) |
| SOV-4 | Operational | 15% | **Strong** | Swiss 24/7 ops, [Swiss-only support option](https://products.vshn.ch/support_plans.html#_option_switzerland_only_support). Platform runs on vanilla Kubernetes |
| SOV-5 | Supply Chain | 20% | **Strong** | Infrastructure-agnostic, [customer chooses provider](https://servala.com/providers/). Open-source tooling — GitLab, Crossplane, OpenTofu, OpenBao |
| SOV-6 | Technology | 15% | **Strong** | Open-source operations tooling. VSHN contributes to [K8up](https://github.com/k8up-io) (CNCF), [Crossplane providers](https://github.com/vshn), [Project Syn](https://github.com/projectsyn) |
| SOV-7 | Security | 10% | **Strong** | [ISO 27001](https://www.vshn.ch/wp-content/uploads/2025/12/ISO-27001-certificate-VSHN-2024.pdf), ISAE 3402 Type II, Swiss SOC. [FINMA-regulated customers](https://www.vshn.ch/en/solutions/solutions-for-banks-and-financial-service-providers/) |
| SOV-8 | Environmental | 5% | **Moderate** | DC operators: Green Datacenter AG (ISO 22301/27001/27701), [Exoscale sustainability](https://www.exoscale.com/sustainability/). [VSHN CSR policy](https://handbook.vshn.ch/corporate_social_responsibility_policy.html) |

**Overall: SEAL-3 equivalent**, the same level achieved by the winners of the EU's own sovereignty tender.

## Make sovereignty a platform property, not an afterthought

When your compliance team or regulator asks "where is your developer platform data and who can access it?", you want a clear answer: Swiss infrastructure, Swiss operations, Swiss law. VSHN gives you that answer without building a 24/7 platform operations team yourself.

[Book a platform assessment](#contact)
