Trust Center
Your data stays yours. We do not train AI models on it and we do not resell it.
This information is only applicable to our Enterprise Platform. Our Free, Basic, Pro and Team users should refer to Disclaimer, Terms of Service and Privacy Policy.
Core Principles
Data Retention
Chat sessions are stored so you can return to them, and there is currently no way to delete one from the interface. A known gap. Uploaded documents are stored against your account; deleting a document removes the stored file. Any other deletion request goes through the Support Center.
Swiss Law, European Hosting
Nerturbo AG is a Swiss company and Swiss law applies. Processing is subject to the GDPR and the Swiss nDSG.
You Own Your Data
You keep ownership of the data you submit and of the outputs generated from it. We do not claim rights to it, resell it, or use it to train AI models. Staff access is limited to operating and supporting the service.
Data Processing & Privacy
Data handling practices compliant with the GDPR and the Swiss nDSG.
- TLS Encryption. All data in transit protected using TLS encryption, including internal connectors, AI queries, and Data Lake requests.
- No AI Training. We do not use customer data to train or improve AI models. Prompts and documents are sent to third-party model providers: through OpenRouter to the model you select, and directly to Google Gemini. What those providers retain is governed by their own terms.
- Logical Separation: Customer data is separated logically between accounts.
- Audit Logs: Document access and changes are recorded in an audit log.
ISO/IEC 27001:2022 Certificate
The information security management system of Nerturbo AG is certified to ISO/IEC 27001:2022 by InterCert (registration IC-IS-2606334, initial certification 29 June 2026, valid to 28 June 2027). The certificate can be verified at intercert.com.
Security Controls
Our information security management system is certified to ISO 27001:2022, and our processing is GDPR and Swiss nDSG compliant. The controls we have in place are listed below, grouped by domain.
Data Security
Endpoint Security
Product Security
Access Management
Security & Continuity
Organization Security
Sub-Processors
These providers process data on our behalf. Each is listed with its purpose and, where it applies, its processing region.
Anthropic
Large Language Model
AWS
Cloud service provider
Cloudflare
Cybersecurity and data protection
Coolify
Web Hosting Provider
DeepL
Machine translation of company register texts
Figma
Visual design and prototyping
GitHub
Source Code Management (SCM)
Google Gemini
Large language model that reads and transcribes uploaded documents
Google Workspace
Workspace productivity and collaboration
Metabase
Analytics and BI
Neo4J
Database for the AI agents and the Graph
Openrouter
AI Platform using in order to access AI models
PostHog
Product analytics and telemetry
Sentry
Monitoring and observability
Slack
Workspace productivity and collaboration
External Trust Center
Policies, security controls and the sub-processor list are also published at: trust-center.graph.swiss
Technical & Organizational Measures
- Physical Access Control: Data centers secured with surveillance, guards, and certified key systems.
- System Access Control: Multi-factor authentication, unique user IDs, complex password policies, and firewall protection.
- Data Access Control: Access on a need-to-know basis only.
- Availability Control: Backup processes and disaster recovery strategies.
Public Procurement
Swiss Graph is registered as a tenderer on SIMAP.ch. CPV codes: 72300000 (Data Services), 72316000 (Data Analysis), 72319000 (Data Supply), 72320000 (Database Services), 72330000 (Data Standardisation & Classification).
View Tenderer Profile on SIMAP
Need More Details?
Our Data Protection Addendum (DPA), Terms of Agreement (TOA) and further compliance documents for Enterprise customers are available in our Trust Center.
Reports & DocumentsThese documents are provided in English only.
For security assessments and custom compliance needs, please use our .
