Security and Swiss Data Residency

The application database, uploaded documents and backups are held in Switzerland. Model inference uses named, contractually bound interfaces. The processing location and contractual boundaries are disclosed before contract. With the separately available Swiss Inference option, the model environment and inference also run in Switzerland. Customer content is not used to train third-party models; the exclusion is recorded contractually. ISO 27001 and ISO 27018 are used as an internal control framework. This is a self-declaration, not certification or independent assurance; the current evidence status is disclosed during the security review.

Status and scope

Last content review: 2026-08-07. These statements cover customer content in the Tendaro product. Contact and demo-request data submitted through the website is described separately in the privacy notice and is not part of the product tiers.

Data residency by tier

The application database, uploaded documents and backups are held in Switzerland. Model inference uses named, contractually bound interfaces. The processing location and contractual boundaries are disclosed before contract.

With the separately available Swiss Inference option, the model environment and inference also run in Switzerland.

The confirmed public boundary is:

Providers, regions, retention periods and further contractual boundaries are specified before contract in the security dossier and data processing agreement. The matrix limits the Swiss commitment to the elements it names explicitly.

Tenant isolation

The current architecture and permission model is described for the selected product tier during the security review. Isolation, storage boundaries and roles are recorded there together with their evidence status. Without that evidence, this public page does not promise a particular technical separation.

No training on customer data

Customer content is not used to train third-party models; the exclusion is recorded contractually.

Encryption

Transport, storage and key-management controls are described in the security dossier with the currently deployed protocol, ownership and evidence status. Until those details are confirmed, this page does not claim a specific TLS or AES version or the use of a hardware security module.

Access management

Available sign-in options, roles and the process for any support access depend on the product tier and agreed deployment. SSO, MFA, approval and logging scope are confirmed before contract; this page makes no cross-tier feature promise about them.

Audit logs and traceability

The security review documents which events are logged, who can access them, whether export is available and how long logs are retained. This page does not claim that every named action is already logged or exportable on every product tier.

Compliance and standards

ISO 27001 and ISO 27018 are used as an internal control framework. This is a self-declaration, not certification or independent assurance; the current evidence status is disclosed during the security review. The review records individually whether, and in which version, a processing register, data processing agreement, subprocessor list and data-flow description are available.

Independent assessment

Whether a current independent assessment report exists is stated in the security dossier with its test date, scope and status. This page claims neither an available report nor a recurring assessment cycle or certification.

Request security documents

Procurement, legal and security teams can request the current document inventory and evidence status by [emailing info@tendaro.ch](mailto:info@tendaro.ch?subject=Tendaro%20security%20documents). The response identifies whether each requested item is available, under review or not yet available and whether an NDA applies; making a request does not imply that every document already exists.

Human in the loop

AI modules provide suggestions, not automated decisions. Bid managers review, amend and approve content before it enters a submission.

Data export and deletion

Export options, retention periods and the deletion process at contract end are documented before contract. This page promises neither a universal retention period nor a particular export format.

Availability

Architecture, recovery objectives and recovery procedures are specified in the security review and agreed service levels. The values in the applicable contract govern.

Frequently asked questions

Where is Tendaro data stored and processed?

The application database, uploaded documents and backups are held in Switzerland. Model inference uses named, contractually bound interfaces. The processing location and contractual boundaries are disclosed before contract. With the separately available Swiss Inference option, the model environment and inference also run in Switzerland.

Are our prompts or drafts used to train AI models?

Customer content is not used to train third-party models; the exclusion is recorded contractually.

Can inference run entirely inside Switzerland?

Yes, as the separately agreed Swiss Inference tier. On Standard, the application database, uploaded documents and backups stay in Switzerland while model inference runs through contractually bound interfaces. On Swiss Inference, the model environment and inference also run in Switzerland. The applicable tier is recorded before contract.

Which tier does our tender require?

That depends on the tender's exact wording. A data-storage requirement is not the same as a requirement that every processing operation take place in Switzerland. Before contract, Tendaro maps the wording to Standard or Swiss Inference and documents the agreed boundary.

What is the ISO and revFADP status?

ISO 27001 and ISO 27018 are used as an internal control framework. This is a self-declaration, not certification or independent assurance; the current evidence status is disclosed during the security review.

How does Tendaro support access work?

Whether support access is possible, and which approval, time and logging boundaries apply, is confirmed for the selected product tier during the security review and recorded contractually.

Related pages

Breadcrumb

More pages

Skip to content