Cedreon in Switzerland
Last updated: 11 August 2026
Cedreon is built in St. Gallen for professionals who cannot simply paste a client file into a chat window. This page sets out the Swiss position: what applies, what we have built, and what we are not claiming.
Data protection under the FADP
Cedreon is operated by SFF S26 AG, a Swiss company. When you use Cedreon to work on your clients' matters, you are the controller and we are the processor, and that relationship runs under the Cedreon Data Processing Agreement, which is incorporated into the Terms of Service. It is in force from the moment you accept the Terms; no separate signature is needed.
The DPA is written for both the revised Swiss Federal Act on Data Protection and the GDPR, because most Swiss firms have EU-facing matters and maintaining two incompatible positions helps nobody. The Privacy Policy describes the data we process as a controller in our own right: your account, your billing, the website.
Where processing actually happens
We will not tell you that everything stays in Switzerland, because it does not.
- The application and your stored data are processed in the European Union.
- The sensitive-value screening, the recognition model, document extraction and the search index run on our own infrastructure and send nothing anywhere.
- AI model requests go through a gateway, on its European endpoint. Every row is pinned to a named European processor with fallback disabled, and each one is named on the subprocessors page rather than in a footnote.
Processing in Europe is not the same as the model having been built there. A firm that needs both can switch its organisation to EU vendors only, which restricts the model set to European-built rows and withholds web search.
What the model provider receives
Before a request leaves, Cedreon screens it and replaces recognised sensitive values with reversible placeholders. The provider receives the placeholder. The mapping is encrypted, and the real values are restored in the reply for you.
This is layered, best-effort recognition. It is not a guarantee that every secrecy-protected element of every input is caught, and we do not describe it as anonymisation. It is one control among several, which is exactly why the Art. 321 agreement below restricts who may receive a request at all rather than relying on screening alone.
Evidence
Every exchange is written to an append-only, hash-chained record: what was screened, which decision was taken, which model answered, how many values were hidden, and when. It does not store the plaintext of your prompts or of the model's answers. It retains integrity and operational metadata, which is more than a sequence proof: identifiers, timestamps, model information, content digests, references to the encrypted stored payload, screening outcomes, policy decisions and token counts. For a professional who has to be able to account for how a client matter was handled, that record is the point of the product.
The Art. 321 agreement
Article 321 of the Swiss Criminal Code binds lawyers, notaries, doctors, dentists, pharmacists, midwives, psychologists and their auxiliary persons. A firm that mandates a technology provider is choosing an auxiliary person, and it needs the provider to accept that position in writing.
Cedreon publishes a Swiss professional-secrecy agreement for exactly that. It is a Swiss instrument under Swiss law, and it is separate from the DPA. It records that Cedreon acts as an auxiliary person, undertakes unlimited-in-time secrecy, binds every individual with any possibility of access, will not disclose to any authority unless compelled by Swiss law binding on us, and will not respond directly to a foreign authority.
Activating it, and what it restricts
The agreement is executed in three steps, and the third is the one that matters technically.
- An authorised administrator of your organisation reviews the agreement and signs it in the organisation console. The server records the exact version, its SHA-256 hash and the timestamp.
- Cedreon countersigns. Until then nothing has changed: a customer signature alone does not activate anything.
- On countersignature the organisation enters the
ch_art321compliance profile, and every member of the organisation is subject to it from that moment.
The profile narrows what you can use. Only routes explicitly approved for it are available: the model picker shows only those models, automatic routing selects only those models, a request for any other model is refused server-side, and external tools whose processors are not approved are switched off for the organisation. Neither EU processing nor a Swiss vendor is by itself enough for approval; approval is a documented decision per route.
If your organisation also has other restrictions, they combine by intersection. Signing another agreement can only ever narrow what is available, never widen it.
Execution produces a downloadable PDF naming both parties, the exact version, the hash and the execution ID. It is an ordinary electronic signature, not a qualified electronic signature under ZertES. Where a qualified signature is required, contact us and we will arrange it through a recognised provider.
Talk to us
Write to [email protected]. If you are subject to professional secrecy and something on this page is not enough for your regulator, tell us which part.