Compliance & security
Alerion is designed from day one for environments where data cannot leak: Swiss hosting, GDPR/FADP compliance, systematic anonymisation before every AI call.
Certifications & standards
- GDPR (EU) and FADP (Switzerland) native compliance — business data and AI content processed in Switzerland or the EU.
- Hosted in Switzerland (Geneva) — application and database on Jelastic (Virtuozzo), backups at Infomaniak — data sovereignty.
- External security audit planned for Q3 2026 — report available to customers under NDA.
- Automatic anonymisation of any personal data before every call to the AI model.
- No data transfer to jurisdictions outside the EU/CH zone — Mistral EU model only.
Security architecture
- TLS 1.3 encryption on all inbound and outbound traffic.
- Zitadel OIDC authentication with mandatory MFA for operators.
- Strict multi-tenant isolation — each client has its own data boundary.
- Append-only immutable audit trail for every sensitive action.
- No raw personal data is ever written to application logs.
Regulated environments
Pharma / GxP
Designed to support the traceability expected in GxP environments: AI-assisted decision history, periodic revalidation, environment separation. Alerion provides evidence — it does not make an organisation compliant.
Finance / FINMA
Designed to support the auditability expected of FINMA-supervised institutions: full audit trail, Swiss hosting, fine-grained access control.
Healthcare
Designed for Swiss and European healthcare actors: systematic anonymisation, native FADP/GDPR, sovereign hosting.
ApprovalGate workflow — sensitive actions under human sign-off
Every irreversible or destructive action goes through a human approval workflow. The operator receives a signed email link (HMAC-SHA256) and must approve explicitly before the action runs. TTL configurable, immutable audit trail.
- Deploy rollback (TTL 1 h) — restoring a previous version in production.
- Tenant deletion (TTL 7 days) — full purge of a multi-tenant client.
- GDPR export (user-initiated) — no operator approval required (Art. 20).
- GDPR delete (TTL 30 days) — right to be forgotten (Art. 17).
- KPI threshold alert — no approval required (automated notification).
Compliance FAQ
Where is the data hosted?
The business data you entrust to Alerion, and the content sent to the AI engine, are processed on infrastructure located in Switzerland or the EU. Some technical sub-processors (payment, code hosting, CDN) may process limited data outside that zone under standard contractual clauses — the full list is on the About page.
How is data sent to the AI model protected?
Any personal data (names, emails, identifiers) is anonymised before being sent to the AI model. Restoration is performed on the Alerion side after the response.
Which AI model provider is used?
Mistral AI, via its European endpoint (api.mistral.ai). No call is routed to non-EU models.
Is an external audit planned?
Yes. An independent external security audit is planned for Q3 2026. The report will be made available to customers under NDA.
Security sheet sent by email after a quick verification (NDA on request).