Where your data lives, who can touch it, and what our AI does with it — in plain language. Swiss-hosted, encrypted, and yours to export any time.
The things a security team actually needs to know — where your data lives, who can reach it, and what leaves your control.
Your data is stored in Swiss and European data centers and stays within Switzerland or the EEA — never silently moved elsewhere.
Everything is encrypted in transit and at rest, behind strict access controls and audit logs over who can reach your data.
AI features are opt-in and Swiss-hosted. Nothing is sent to an AI service unless you trigger it, and we never train models on your data.
Export everything you put in, any time, in standard formats. Your compliance data is yours to take with you.
Every subprocessor is bound by a data processing agreement and must meet GDPR requirements. Below is the full list — who they are, where they sit, and what data each one touches.
Certifications listed are held by each provider, not by devguard.
| Service Provider | Location | Data Processed | Last Updated | Compliance |
|---|---|---|---|---|
| Switzerland (eu-central-2) | Cloud Infrastructure Emails (SES), AI processing (Bedrock) | 13.11.2025 | ISO 27001GDPRSOC 2 | |
| Global Network | CDN, DDoS Protection, Security & Edge Network Services Network traffic metadata, security logs, CDN-cached content | 13.11.2025 | ISO 27001GDPRSOC 2 | |
| Switzerland (Exoscale) | Cloud Hosting & Managed Infrastructure SaaS application data, user data, backups, logs | 13.11.2025 | ISO 27001GDPRFADP | |
| European Union | Communication & Productivity Suite Emails, documents, calendar data, anonymized operational analytics | 13.11.2025 | ISO 27001GDPRSOC 2 | |
| European Union | Product Analytics Anonymous usage analytics only | 13.11.2025 | ISO 27001GDPR | |
| European Union | Application Monitoring & Error Tracking Anonymous error and performance data only | 13.11.2025 | ISO 27001GDPRSOC 2 | |
| European Union | Payment Processing Payment information, billing details, subscription and invoicing data | 13.11.2025 | ISO 27001GDPRSOC 2 |
We are transparent about the data we collect and how we use it. We only collect data necessary to provide and improve our services.
These include standard personal data necessary for providing our services.
These include employment-related data necessary for HR, payroll, and operational purposes.
Payment details are handled exclusively by certified third-party payment providers.
These include also particularly sensitive personal data according to swiss law.
For more information about our data collection practices, please refer to our Privacy Policy.
AI is not the core of our product but can be used to enhance your workflows. All AI features can be disabled at any time.
AI features are enabled by default but can be disabled at any time in your settings. No data is sent to AI services unless you explicitly trigger an AI-powered action.
devguard is a compliance platform first. AI serves as an optional enhancement to help with tasks like drafting policies or suggesting control mappings. The platform is fully functional without any AI features enabled.
When AI features are used, processing is handled through AWS Bedrock hosted in Switzerland (eu-central-2) using closed-source foundation models. We do not train or fine-tune any models on customer data.
Find answers to common questions about our security practices and data handling.
We protect your data with multiple layers of security: encryption at rest and in transit, strict access controls, and continuous monitoring. All data is stored in Swiss or European data centers, under Swiss and EU data protection regulations.
We don't yet hold formal certifications of our own. We build to industry best practices aligned with ISO 27001 and GDPR, and our infrastructure providers maintain these certifications, giving the platform a secure foundation. Formal certification is on our roadmap as we grow.
Your data is primarily stored in Swiss data centers operated by Divio and AWS. We ensure all data remains within Switzerland or the European Economic Area (EEA) unless explicitly required for specific services like payment processing.
Access to customer data is strictly limited to authorized personnel who need it to provide and improve our services. All employees sign confidentiality agreements and undergo security training. We maintain detailed audit logs of all data access.
Security is part of how we build, not a separate event. Every change goes through code review, our dependencies and infrastructure are automatically scanned for known vulnerabilities, and we monitor our systems continuously. As devguard grows, we're working toward formal third-party penetration testing and audits.
You can request data deletion at any time by contacting our support team or through your account settings. We will process your request within 30 days in accordance with GDPR requirements, except where we are legally required to retain certain information.
In the unlikely event of a data breach, we have an incident response plan that includes immediate containment, investigation, and notification procedures. We will notify affected customers within 72 hours as required by GDPR, along with detailed information about the incident and mitigation steps.
Yes. You can export your data yourself at any time: every list view, from risks and assets to vendors and actions, exports to CSV, and all ten report types export to PDF. For a full export or anything the in-app tools don’t cover, our support team can help.
Found a security issue? Contact us at the email below — we welcome and appreciate your contribution to safety.
No bounty program yet,
but we welcome responsible disclosure.
Built with the precision and reliability Switzerland is known for, and hosted here too. A strong fit for teams meeting strict European standards like ISO 27001 and GDPR — where data privacy isn't a nice-to-have.
We're early, and the teams using devguard now help shape what it becomes. Tell us what's missing, and there's a real chance you'll see it ship.