Security & Data Protection

Swiss-built. Swiss-hosted. Swiss-compliant. Enterprise-grade security with role-based access control, organization isolation, and encryption throughout the platform. Fully FADP & GDPR compliant. AI processing never stores your data.

Product Security

  • Audit Logging
  • Role-Based Access Control
  • Organization-Based Access Control

Data Security

  • Automated Data Backups
  • Complete Data Erasure
  • Encryption at Rest (AES-256)

Infrastructure

  • Swiss-Hosted Platform
  • Enterprise-Grade Infrastructure
  • Disaster Recovery

AI Security

  • Secure AI Processing
  • AI Governance Controls
  • No Training on Your Data

Legal

  • Subprocessors List
  • Data Processing Agreement
  • Governance Confidentiality

Data Privacy

  • FADP Compliant
  • GDPR Compliant
  • Swiss Data Residency

Corporate Security

  • Incident Response
  • Vendor Management
  • Security Training

Compliance

  • Independent Security Review
  • FINMA Ready
  • Continuous Monitoring

Access Control

  • Zero Trust Architecture
  • Supabase Authentication
  • Organization Isolation

Security Documentation

Request detailed security documentation for your security review.

Product

Technical Documentation

Legal

Data Processing Agreement

Legal

Subprocessors List

Security Deep-Dive

A detailed look at our security architecture, data residency, AI processing flow, and compliance measures.

Enterprise-Grade Security

Votaris is built to meet the security and privacy standards of Switzerland's most demanding organizations. Our architecture is designed from the ground up to protect sensitive governance data, preserve confidentiality, and provide the transparency governance and IT teams require.

Every aspect of the platform, from role-based access control and organization isolation to encryption and audit logging, is built around the trust and confidentiality that governance work demands.

Encryption Everywhere

All data is encrypted in transit with TLS 1.3 and at rest with AES-256 encryption across all providers. No exceptions.

Organization Isolation

Strict data separation ensures users access only their organization and assigned spaces, enforced at every level of the stack.

Swiss Data Residency

Data and files stay in Switzerland (Supabase). AI inference runs in Switzerland (AWS Bedrock); text fragments stay in Pinecone Ireland.

Regulatory Compliance

Designed for regulated industries. FADP & GDPR compliant, with provider DPAs and FINMA-ready cloud providers contracted as auxiliary persons.

Data Isolation: Your Data, Completely Separated

Votaris implements comprehensive data isolation at every level. Role-based access control ensures users can only access assigned spaces, while organization-scoped queries keep your governance data completely separate. Here is what this protects:

Governance Documents

Each space has its own secure document library with dedicated vector storage for AI-powered semantic search.

AI Conversations

All AI conversations are scoped to your space. Chats are private by default and can be shared with space members when needed.

Organization Data

Strict tenant separation ensures complete isolation between organizations at every level of the stack.

Meeting Records

All meeting data—agendas, minutes, votes, decisions, and signatures—remains private to your space and organization.

Audit Trails

Complete audit trails for security and compliance purposes, scoped to your organization and visible only to owners.

Secure Storage

All file attachments and uploaded documents are stored in Switzerland with organization-level access controls.

All data is protected by strict access controls, encrypted at rest using AES-256 encryption, and governed by Swiss data protection law. Organization owners can immediately revoke access by deactivating the organization.

How AI Processing Works

We use AWS Bedrock in Switzerland to power our AI assistant. Your data is never stored by the AI provider or used for training. Here is exactly how processing works:

1

You send a message from your browser

Your question is sent over an encrypted TLS connection to Votaris servers hosted on Vercel (Frankfurt, EU).

2

Votaris enriches your query

Your message is combined with relevant context from your governance documents, meeting minutes, and tasks through our RAG pipeline, powered by Pinecone (Ireland, EU).

3

Encrypted call to AI infrastructure

The prepared prompt is sent over an encrypted connection to AWS Bedrock in Switzerland. This transmission takes a fraction of a second.

4

Processing happens entirely in memory

The AI model processes your prompt entirely in memory. No data is written to disk. No data is stored. No data is used for training. No human ever sees your prompt.

5

Response returns and is stored securely

The AI response streams back to you in real time and is stored in your conversation history in Supabase (Switzerland) with a full audit trail.

Compliance & Legal Assurance

Votaris is designed to meet the compliance requirements of Swiss corporations, foundations, and regulated institutions. From day one, our architecture has been built around Swiss data protection law and governance confidentiality obligations.

FADP & GDPR Compliance

Fully compliant with Swiss FADP and EU GDPR. Ireland is on the Swiss adequacy list, so no additional safeguards are required for Pinecone data.

Encryption Standards

AES-256 encryption for all data at rest and TLS 1.3 for all data in transit. Industry-leading encryption protocols protect your data at every stage.

FINMA Compliance

Cloud providers contracted as auxiliary persons. No approval needed under FINMA guidelines. DPAs signed with all providers: Supabase, AWS Bedrock, Pinecone, and Vercel.

No Training on Your Data

Your data is never used to train AI models. Strict contractual agreements with our AI infrastructure providers prohibit the use of customer data for model training.

For compliance inquiries, contact security@devigus.com →

Ready to transform your governance?

Run meetings, manage documents, and make decisions with AI-assisted workflows and Swiss data protection. No compromises on security or compliance.

Votaris AI – Security – Swiss-built AI governance workspace