Application Operations Sovereignty: Your Product, Swiss Operations

When a regulated customer buys your software as a managed service, they inherit your operations provider's jurisdiction. If your operations run on US hyperscaler infrastructure, your customer's data falls under the CLOUD Act, accessible to US authorities without Swiss judicial process, regardless of which region you select.

For ISVs selling into Swiss finance, healthcare, and government, this is a deal-breaker. Your customers need Swiss data residency and a Swiss operations provider to pass due diligence.

VSHN operates your software on Swiss infrastructure from Cloudscale or Exoscale, or on your customer's own premises. Swiss company, Swiss law. Your customers' data stays under Swiss jurisdiction.

Why VSHN operations strengthen your sovereignty story

  • Swiss company, Swiss law: VSHN AG is incorporated in Switzerland with all shareholders Swiss citizens. No foreign parent, no CLOUD Act exposure
  • Infrastructure you choose: Each customer instance runs on Cloudscale, Exoscale, or customer premises, with no hyperscaler dependency
  • On-premises option: When regulation or contract requires it, VSHN operates your software inside your customer's data center with the same 24/7 operations
  • Swiss operations team: with the Swiss-only support option, every access to your customers' systems, including manual change rollouts, happens from within Switzerland
  • ISO 27001 certified: Since 2017, with ISAE 3402 Type II attestation
  • Your compliance evidence: VSHN's certifications and regulated-industry references (HIN, Finnova, acrevis, Swiss Federal Archives) become part of your customer's due diligence package

Get a cost estimate

Operations sovereignty compared

Dimension Your ops on AWS/Azure/GCP Your ops team in-house VSHN Application Operations
Governing law US law Your jurisdiction Swiss law
CLOUD Act Exposed Not exposed Not exposed
Data location Configurable (US-controlled) Your choice Switzerland or customer DC
Staff access from abroad Your team, plus hyperscaler staff worldwide Your hires VSHN Canada for night-time scheduled work; none with the Swiss-only option
24/7 coverage Vendor-dependent 4-6 FTE minimum Included from CHF 800/month
Compliance evidence Vendor's certifications You build from scratch ISO 27001, ISAE 3402, named references
On-premises Not available You manage VSHN manages on customer site

Compliance and regulatory readiness

VSHN operations support your customers' compliance requirements:

  • FINMA Circular 2018/3: Outsourcing requirements for Swiss financial institutions. VSHN provides audit documentation, Swiss-only operations, and contractual commitments for regulated customers
  • EU DORA (Digital Operational Resilience Act): ICT third-party risk management provisions. Not directly binding in Switzerland, but Swiss-hosted operations with documented SLAs align with DORA's requirements for critical ICT service providers, relevant for customers with EU operations
  • NIS2 Directive: Supply chain security requirements for essential and important entities. VSHN's ISO 27001 controls map to NIS2 Article 21 requirements
  • GDPR / Swiss DPA: Swiss data residency by default. EU adequacy decision covers Swiss-EU data transfers

VSHN sovereignty self-assessment

We applied the EU's Cloud Sovereignty Framework (v1.2.1, October 2025) to our own services. This framework was used to score providers in the EU's EUR 180M sovereign cloud tender in April 2026. Three pure-European providers achieved SEAL-3, while a consortium involving Google Cloud scored only SEAL-2.

This is a self-assessment, not a formal SEAL certification. We publish it for transparency so customers can evaluate our sovereignty profile using the same structured criteria the EU uses.

# Dimension Weight Assessment Evidence
SOV-1 Strategic 15% Strong Swiss AG, no foreign parent, all shareholders Swiss citizens (Commercial Register)
SOV-2 Legal 10% Strong Swiss law (GTC), no CLOUD Act, EU adequacy decision
SOV-3 Data & AI 10% Strong Swiss DCs by default. Sovereign key management via Managed OpenBao + Swiss HSM
SOV-4 Operational 15% Strong Swiss 24/7 ops, Swiss-only support option. All services on vanilla Kubernetes
SOV-5 Supply Chain 20% Strong Infrastructure-agnostic, customer chooses provider. Open-source tooling
SOV-6 Technology 15% Strong Open-source operations tooling. VSHN contributes to K8up (CNCF), Crossplane providers, Project Syn
SOV-7 Security 10% Strong ISO 27001, ISAE 3402 Type II, Swiss SOC. FINMA-regulated customers
SOV-8 Environmental 5% Moderate DC operators: Green Datacenter AG (ISO 22301/27001/27701), Exoscale sustainability. VSHN CSR policy

Overall: SEAL-3 equivalent, the same level achieved by the winners of the EU's own sovereignty tender.

Make sovereignty part of your product

When your regulated customers ask "where is my data and who can access it?", you want a clear answer: Swiss infrastructure, Swiss operations, Swiss law. VSHN gives you that answer without building an operations team yourself.

Get a cost estimate for Swiss-operated application operations.

Get a cost estimate for operating your software

Tell us about your product, how your customers consume it, and the SLA and compliance they require. A VSHN architect will propose a tailored operations setup with transparent per-instance pricing. No commitment required.

Book a free call

Or ask your question