Trust & Compliance
Everything your risk and compliance team needs to know about us. On one page.
Certifications, regulatory readiness, AI governance, and data handling – precisely worded and backed with evidence, so your review goes faster.
Certifications, regulatory readiness, AI governance, and data handling – precisely worded and backed with evidence, so your review goes faster.
| Framework | Our status | What that means in practice |
|---|---|---|
| GDPR / revFADP | compliant | Standard DPA contracts, documented TOMs, EU/CH data hosting selectable |
| DORA | delivery-ready | ICT third-party requirements reflected in our contracts; audit rights, exit strategy, incident reporting chains defined |
| EU AI Act | prepared | AI use in the SDLC documented and classified; human oversight provable (framework gates) |
| FINMA context | project-proven | Experience with outsourcing-circular requirements in banking/insurance projects |
| NIS2 / critical infrastructure | project-proven | Secure-SDLC evidence for operators of critical infrastructure (energy, transport, telecom) |
A Swiss corporation (Pfäffikon SZ) as your single contracting party – one point of contact, one legal framework.
Data and code hosting in CH/EU selectable; access concepts documented per project.
Engineering hubs in Serbia, Romania, Moldova – under uniform Swiss quality and security governance.
All facts on this page as a PDF – for vendor reviews and risk assessments.
A joint call with your colleagues – we bring the evidence.