Your developer platform, your data, your jurisdiction
When a regulated organization runs its developer platform on a US hyperscaler, every pipeline run, secret, audit log, and code artifact falls under the CLOUD Act. US authorities can compel access without Swiss judicial process, regardless of the region selected. For organizations in Swiss finance, healthcare, and government, this is not a theoretical risk: it is a compliance gap that due diligence reviews are catching.
VSHN operates your internal developer platform on Swiss infrastructure: Swiss company, Swiss staff, Swiss law. Your data stays in Switzerland.
Why VSHN-operated platforms strengthen your sovereignty
- Swiss company, Swiss law: VSHN AG is incorporated in Switzerland. No foreign parent, no CLOUD Act exposure
- Open-source stack, no vendor lock-in: GitLab, Crossplane, OpenTofu, and OpenBao are community-governed open-source projects. No hyperscaler proprietary APIs in the critical path
- ISO 27001 certified: Since 2014, with ISAE 3402 Type II attestation covering the operational controls that protect your platform
- GitOps audit trail: Every change to your platform configuration goes through Git. Full audit history of who changed what and when, suitable for regulatory inspection
- Cloud choice: Run on Cloudscale, Exoscale, or your own Azure tenant in Switzerland. You decide where compute and storage run
- Swiss operations team: All on-call engineers are based in Switzerland. Swiss-only support option available for regulated requirements
Sovereignty compared
| Dimension | DIY (self-operated) | Hyperscaler managed | VSHN-operated |
|---|---|---|---|
| Governing law | Your jurisdiction | US law | Swiss law |
| CLOUD Act | Not exposed | Exposed | Not exposed |
| Data location | Your choice | Configurable (US-controlled) | Switzerland or customer DC |
| Operations team | Your hires (4-6 FTE min) | Vendor staff | Swiss-based VSHN engineers |
| Audit trail | You build it | Vendor logs (limited access) | GitOps history, full export |
| Vendor independence | Full | Proprietary APIs | Open-source, portable |
| Compliance evidence | Build from scratch | Vendor shared-responsibility | ISO 27001, ISAE 3402, named references |
Compliance and regulatory readiness
VSHN-operated developer platforms support your organization's compliance requirements:
- FINMA Circular 2018/3: Outsourcing requirements for Swiss financial institutions. VSHN provides audit documentation, Swiss-only operations, and contractual commitments for regulated customers
- EU DORA (Digital Operational Resilience Act): ICT third-party risk management provisions. Swiss-hosted operations with documented SLAs meet DORA's requirements for critical ICT service providers
- NIS2 Directive: Supply chain security requirements for essential and important entities. VSHN's ISO 27001 controls map to NIS2 Article 21 requirements
- GDPR / Swiss DPA: Swiss data residency by default. EU adequacy decision covers Swiss-EU data transfers
VSHN sovereignty self-assessment
We applied the EU's Cloud Sovereignty Framework (v1.2.1, October 2025) to our own services. This framework was used to score providers in the EU's EUR 180M sovereign cloud tender in April 2026. Three pure-European providers achieved SEAL-3, while a consortium involving Google Cloud scored only SEAL-2.
This is a self-assessment, not a formal SEAL certification. We publish it for transparency so customers can evaluate our sovereignty profile using the same structured criteria the EU uses.
| # | Dimension | Weight | Assessment | Evidence |
|---|---|---|---|---|
| SOV-1 | Strategic | 15% | Strong | Swiss AG, no foreign parent, all shareholders Swiss citizens (Commercial Register) |
| SOV-2 | Legal | 10% | Strong | Swiss law (GTC), no CLOUD Act, EU adequacy decision |
| SOV-3 | Data & AI | 10% | Strong | Swiss DCs by default. Sovereign key management via Managed OpenBao + Swiss HSM |
| SOV-4 | Operational | 15% | Strong | Swiss 24/7 ops, Swiss-only support option. Platform runs on vanilla Kubernetes |
| SOV-5 | Supply Chain | 20% | Strong | Infrastructure-agnostic, customer chooses provider. Open-source tooling — GitLab, Crossplane, OpenTofu, OpenBao |
| SOV-6 | Technology | 15% | Strong | Open-source operations tooling. VSHN contributes to K8up (CNCF), Crossplane providers, Project Syn |
| SOV-7 | Security | 10% | Strong | ISO 27001, ISAE 3402 Type II, Swiss SOC. FINMA-regulated customers |
| SOV-8 | Environmental | 5% | Moderate | DC operators: Green Datacenter AG (ISO 22301/27001/27701), Exoscale sustainability. VSHN CSR policy |
Overall: SEAL-3 equivalent, the same level achieved by the winners of the EU's own sovereignty tender.
Make sovereignty a platform property, not an afterthought
When your compliance team or regulator asks "where is your developer platform data and who can access it?", you want a clear answer: Swiss infrastructure, Swiss operations, Swiss law. VSHN gives you that answer without building a 24/7 platform operations team yourself.