SECURITY Swiss‑resident. EU‑processed. Audit‑ready.

Your data is in safe hands.

WealthComply processes some of the most sensitive material in private wealth. Data is stored in Switzerland, AI runs inside the EU, and nothing is ever used to train a model. Here is exactly how it works.

Looking up between three towers
Standards & compliance

We hold ourselves to the frameworks our clients are judged against — and we are candid about where each one stands.

ISO 27001 In progress

We operate an ISO 27001‑aligned ISMS in production today — documented policy, control register, named ownership — with formal certification on a scheduled timeline. Our leadership has taken a comparable platform through certification before.

ISO 42001 On roadmap

The international standard for AI management systems is on our certification roadmap. Our AI governance already mirrors its requirements: a model inventory, an AI‑specific risk register, and a record for every AI‑assisted output.

GDPR & Swiss FADP Compliant

The platform is designed to satisfy UK GDPR, EU GDPR and the revised Swiss FADP simultaneously, with a DPA, subprocessor register and DPIA support ready for your data‑protection team.

DORA Aware

DORA is not a certification, so we do not claim one. Our incident notification, third‑party risk and operational‑resilience practices are built to support clients whose regulators expect DORA‑aligned discipline from material ICT vendors.

A full evidence pack — Statement of Applicability, policy set, architecture documentation and control register — is available under NDA.

Where your data lives

Swiss‑resident by default

All customer data — entities, controlling persons, documents, audit history and encrypted backups — is stored at rest in Azure Switzerland North, and stays there.

AI processed inside the EU

Classification reasoning runs on Azure OpenAI in West Europe, within the EU data boundary. We will move to Swiss‑region capacity as Microsoft makes it generally available.

No US processing

No customer data is routed to, processed in, or stored in the United States. Region pinning is enforced by Azure Policy to prevent accidental cross‑region deployment.

No model training on your data

Your data is never used to train, fine‑tune or evaluate any AI model. This is both an Azure OpenAI configuration and a contractual commitment in our DPA.

Encryption & access

Encrypted in transit and at rest

TLS 1.2+ with HSTS on every public endpoint; AES‑256 across all databases, object storage, queues and logs. Backups remain encrypted and within Switzerland.

Default position: no access

WealthComply staff cannot read your classifications, controlling‑person data or documents without written, time‑bound, logged approval from your administrator — recorded in your own audit trail.

Role‑based by design

Permissions map to how compliance teams work — Reviewer, Officer, Administrator and Auditor — with SSO via Microsoft Entra ID and MFA enforceable per workspace.

Defence in depth

Cloudflare WAF and DDoS protection at the edge, private endpoints to datastores, Microsoft Defender for Cloud, and peer‑reviewed, pipeline‑controlled deployments.

AI governance

The intelligence is powerful. The handling is conservative.

EU‑only inference

Azure OpenAI in West Europe, within the EU data boundary. No routing to the US, no consumer AI services.

Never trained on your data

Contractually prohibited and technically configured. Our own evaluation uses synthetic or permissioned material only.

Every output evidenced

A structured rationale, the source documents cited, a calibrated confidence indicator, and the model version — recorded with each result.

You confirm, always

The people using WealthComply confirm the underlying data and approve the output. The platform informs the review; it does not replace it.

The vendors behind the vendor

Microsoft Azure — Switzerland North

Core hosting, database, storage and monitoring. Full platform data, resident in Switzerland.

Azure OpenAI — EU (West Europe)

AI inference for classification reasoning. Entity and document content during processing only — never retained for training.

Cloudflare & Microsoft Entra ID

Edge protection, WAF and DDoS mitigation; identity and SSO. Technical metadata and authentication tokens — no customer content.

Optional, and disable‑able

Non‑essential telemetry (e.g. error monitoring) can be disabled per tenant for clients with the strictest Swiss‑only requirements. Clients are notified of material subprocessor changes with the right to object.

FAQ

Where exactly is our data stored?
All customer data is stored at rest in Azure Switzerland North — entities, classifications, controlling persons, uploaded documents, audit history and encrypted backups. AI inference uses Azure OpenAI in West Europe, within the EU data boundary. No customer data is processed in or stored in the United States.
How is our data encrypted?
In transit with TLS 1.2+ and HSTS on all public endpoints; at rest with AES‑256 across all Azure‑managed databases, object storage, queues and logs. Secrets and keys are held in Azure Key Vault with role‑scoped access, and backups remain encrypted within Switzerland.
Is our data used to train any AI model?
No. Customer data is never used to train, fine‑tune or evaluate any foundation model. This is enforced both contractually in our DPA and technically through Azure OpenAI's enterprise data‑handling configuration. Every AI‑assisted output carries a rationale, source citations, a confidence indicator and the model version used.
Are you ISO 27001 or SOC 2 certified?
We are not yet formally certified. We operate an ISO 27001‑aligned ISMS in production today and are completing formal certification on a documented timeline, led by people who have achieved it before for a comparable platform. We can map our controls to SOC 2 Trust Service Criteria and share the underlying evidence, including our Statement of Applicability, under NDA.
Can your support team see our data?
Not by default. Support staff can only read your content with a documented, time‑bound, ticket‑referenced access grant from your administrator, and every such access is logged in your audit trail with the engineer's identity. Privileged production access uses just‑in‑time elevation through Entra ID PIM.
What happens to our data if we leave?
You receive a full export of your tenant data in formats agreed in advance (typically CSV/JSON, with documents in their original format). After the export window, your tenant is securely deleted unless a documented legal hold applies.
How quickly would you tell us about a breach?
Within 72 hours of a confirmed personal data breach, with material updates as the investigation develops and a written post‑incident review where appropriate. Incident response is owned by our security lead and supported by scheduled tabletop exercises.
Can we run our own security review?
Yes. We provide an evidence pack under NDA — Statement of Applicability, architecture documentation, contractual controls and penetration‑test summaries — and our terms grant audit rights to clients and, on request, their competent regulator.

Serious about security?

Book a demo, or ask for the full evidence pack.

Book a demo