AI security · Digital sovereignty for Switzerland

The AI Data Firewall

Data loss prevention, rebuilt for the age of AI: one guard for your people and your AI agents, with full visibility into shadow AI and its costs. On our own servers in a Swiss datacenter, under Swiss law.

How it works
Every AI interaction, inspected in Switzerland
live
Employeesbrowser · desktop · apps
Internal AI & agentscopilots · RAG · workflows
Customer-facing AIchatbots · voice agents
NativeAI GuardCH · OWN SERVERS
PII → anonymizedcustom data structures → maskedsensitive documents → blockedsensitive semantic context → blockedinjection → strippedjailbreak → blockedeverything → logged
External LLMsGPT · Claude · Gemini · Copilot · DeepL · all AI tools your employees use
← receive clean, minimal prompts only
External tool callsweb search · code execution · CRM & ticketing · calendar & email · external AI services
← queries and parameters inspected too
No public cloud. Ever.
SWISS LAWSWISS COMPANYSWISS DATACENTEROUR OWN SERVERS IN SWITZERLAND

Why now

Data compliance is no longer optional.

CHF 250k
Personal criminal liability

The Swiss DSG fines the responsible individual, not the company. Art. 47 BankG and Art. 321 CP add criminal statutes for banking and patient secrecy. One uncontrolled prompt is a potential disclosure.

Aug 2026
EU AI Act: high-risk rules

Clinical AI, credit scoring, insurance pricing and public-sector AI become regulated high-risk systems, with binding logging, oversight and governance duties. Fines up to EUR 35 million or 7% of turnover.

FISA 702
US extraterritorial access

Every prompt sent to a US-domiciled LLM provider can be accessed by US authorities. The Cloud Act applies wherever the data sits. Data on our servers in Switzerland is protected.

See it in action

Omnichannel protection, across all devices.

ChatGPT, Claude, Gemini, Copilot, DeepL and whatever your employees try next week: the same policies, anonymization and audit trail on the work laptop and the work phone.

See scenarios →

Customer profile for Thomas Brunner, 14.03.1981, AHV 756.1234.5678.97. Update his address to Seestrasse 42, 8002 Zürich. Draft the internal CRM request.

Customer profile for <PERSON>, <DATE>, AHV <CH_AHV>. Update his address to <LOCATION>. Draft the internal CRM request.

Here is the customer list:

Q3_Kundenliste.xlsx (2,400 rows)

NativeAI Guard, BLOCKED: Blocked attachment: Q3_Kundenliste.xlsx. Blocked by policy: Customer Data Leakage Prevention.

Products

Two use cases.
One tool.

Everyone talks about sovereign cybersecurity. We are making it a reality: a Swiss solution, designed, built and hosted together with the Swiss institutions that want to protect themselves with a national solution.

Seen in the field

Your best people leak the most data.

Three scenarios from real conversations with Swiss security leaders. They are probably happening in your organization right now.

USE CASE 01
The CRM export

A marketing manager exports the full customer database to CSV and uploads it to ChatGPT to build campaign segments. It works beautifully. Every customer record just left the company, in one prompt.

NativeAI Guard: inspects the upload, detects the customer records and blocks the file before it leaves the company, with an explanation for the employee.
USE CASE 02
The invisible upload

Grammarly and Copilot send text to cloud APIs as your employees type. Legal pastes contracts into DeepL daily. Nobody "uploaded" anything, and traditional DLP never fires.

NativeAI Guard: covers the whole web surface (translation tools, writing assistants, every AI app), not just the chatbots you know about.
USE CASE 03
The agent nobody watches

An internal agent calls OpenAI's API directly from backend code. Your browser extension, web proxy and CASB never see the traffic. Sensitive data flows out through a channel with zero controls.

NativeAI Guard: the API proxy inspects agent-to-API traffic like any prompt: DLP, policies and logging for machines, not just people.

Where your data actually ends up

Sovereign, down to the datacenter.

Not a "Swiss region" of a US hyperscaler: servers we own, in a Swiss datacenter, under Swiss law. No layer of the stack is subject to the US Cloud Act.

LAYER 04Swiss lawjurisdiction, no Cloud Act reach
LAYER 03Swiss companybuilt and run by Swiss engineers
LAYER 02Swiss datacenterno public-cloud dependency
LAYER 01Servers we ownyour data stops here

Three modes: transient (nothing stored), anonymized storage, or a full prompt audit trail. Swiss SaaS on our hardware, or on-premises on yours.

OUR OWN SERVERS · SWISS DATACENTER IN LAUSANNENO PUBLIC CLOUD

Industries

Deployed where leaking data is not an option.

Obligations coveredSwiss DSGGDPREU AI ActFINMA 08/2024DORANIS2Art. 47 BankGArt. 321 CPArt. 35 VAGArt. 84 KVG

Start with a pilot phase that we run for you.

One month, observation only, no changes to workflows, we run it end to end. The result: a risk overview of data leaks, shadow AI, AI usage and model costs for your management.

Contact us