Data sovereignty
Why your workspace belongs in Switzerland
Where your workspace runs decides which laws reach your data. Rhaetix is built, operated and hosted in Switzerland — by design, not as an afterthought.
Two ways to run a workspace
A typical US cloud suite
- Subject to the US CLOUD Act, wherever the data centre is
- The provider holds the keys and can access content
- Applicable law: United States
Rhaetix
- Swiss company under Swiss law, outside the CLOUD Act
- End-to-end encrypted messaging: we couldn’t read it if we wanted to
- Applicable law: Switzerland
The CLOUD Act problem
The US CLOUD Act (2018) allows US authorities to compel US-based service providers to hand over data in their possession, custody or control — regardless of where in the world that data is stored. An EU or Swiss data centre does not change this: what matters is who controls the provider.
If your workspace runs on a US cloud suite, this legal reach extends to your documents, mails and messages. As a Swiss company with no US corporate presence, Rhaetix is outside the CLOUD Act’s reach.
Swiss privacy law
Switzerland has one of the world’s strongest privacy traditions. The revised Federal Act on Data Protection (nFADP, 2023) sets strict rules for handling personal data, and Switzerland is recognised by the EU as providing an adequate level of data protection.
Disclosure to foreign authorities runs through Swiss legal assistance procedures — with Swiss courts involved, not foreign administrative orders.
Sovereignty in practice, not just on paper
Jurisdiction is only half the story. Rhaetix adds the technical half: end-to-end encryption means your content is encrypted before it leaves your device, with keys that stay with you. Even under legal compulsion, what we could hand over is ciphertext.
And if you want zero dependence on any provider — including us — you can self-host the entire workspace on your own infrastructure.