Security and privacy

Where your data lives

Custodos stores your data in Switzerland, and AI models work in the region your admins choose. How storage, region and model fit together.

"Where is our data?" covers two different things: where Custodos stores your data, and where an AI model processes a message. The first is fixed. The second is your admins' choice, made with the processing region.

Storage

WhatWhere
Application and database: chats, uploaded files, Company Brain, agents, user accountsSwitzerland
BackupsZurich, encrypted before upload; the storage provider has no access to the plain text
Delivery of sign-in emailsSwitzerland
Payment processing, only for paid useEU and USA, billing data only, never chat, file or prompt content

The companies that provide these services are listed in annex 3 of the DPA (in German) and in the privacy policy.

Processing: the processing region

Admins choose the region under Models, in the section Processing region. It applies to the whole workspace.

RegionWhat it means
SwitzerlandOnly models that process in Switzerland. Far fewer models are available, and web search is unavailable because search queries would leave Switzerland.
European UnionOnly models that process in the EU.
EU + SwitzerlandBoth regions. The default, and recommended.
GlobalAdds models without a residency commitment, which may process anywhere in the world, for example directly at OpenAI in the USA. This is an explicit decision by your admins.

The region applies everywhere, not only in the model picker. A model outside the region disappears for every member, including as the fallback when credits run out. The same goes for image generation and for the model that prepares brain documents for search. A member cannot get around the region: Custodos checks it on the server on every request.

The “Chat models” section with the presets, the region filter and model cards showing a switch and the credits per answer.

Where a single model runs

In the model picker, every model carries a small mark and a line saying where it runs, for example "Hosted in the EU on Google Cloud". The marks mean:

MarkMeaning
Swiss crossProcessed in Switzerland.
German flagSingle region, processed in Germany.
EU starsProcessed inside the EU. The exact country is not fixed: the provider may serve from any of its EU regions.
GlobeProcessed on the provider's worldwide infrastructure, with no residency commitment. Only available when the region is set to Global.

Under Models, in a model's Details, admins also see how the location is guaranteed:

ResidencyWhat stands behind it
EnforcedThe provider's endpoint serves only the committed region and refuses everything else. The location cannot change unnoticed.
VerifiedThe endpoint is bound to one region, and its addresses can be checked against the published address ranges of that region.
ContractualThe region is set on every request and the provider commits to it by contract, but it cannot be measured from outside.

The list of models changes over time. Your admins can see the current list, with location and residency, under Models at any time.

What else goes to third parties

When web search is on, only the search query the model writes goes to a European search index based and operated in France. The conversation is never sent. In the "Block" and "Pseudonymise" protection modes, a query containing an AHV number, IBAN, card number or UID number is not sent. Security mode never searches. Admins can switch web search off at any time, see Managing web search.

Context cache

To avoid reprocessing the whole conversation with every message, the model provider may keep a computed intermediate representation of it for a limited time. It stays with the same provider, in the same region, that processes the message anyway; no further recipient is added. Every workspace has its own key that cannot be guessed, so a cache hit across customers is ruled out. If a brain's sharing or the data protection setting changes, the key changes with it. Where the workspace pseudonymises, the cache holds the placeholders, not the real values. Your admins choose the duration, see Retention and context cache.

Connected accounts

Each person connects Google Drive, Microsoft 365 and Outlook with their own account. Custodos reads only what you ask for there, and checks the text against the workspace's data protection settings, like an upload, before it reaches a model. Imported documents are stored as text only; the original file stays with the provider. An image from a connected account is handled like an image you attach directly. Outlook emails are never sent: replies are saved as drafts in your mailbox. Custodos adds a meeting with attendees only once you have confirmed the proposal, and Outlook then sends the invitations. More under Integrations overview.

This page is a summary. The privacy policy and the DPA (in German) in their current version are authoritative.

Frequently asked questions

Next steps

On this page