Glossary

The terms that come up when an organisation decides where its software runs and who operates it, defined in a sentence and explained in a page.

Talk to our team

Air-gapped system

An air-gapped system is a computer or network physically or logically isolated from the internet and from other untrusted networks, so data can enter or leave only through a controlled transfer process.

Bring your own cloud (BYOC)

Bring your own cloud is a deployment model in which a vendor runs its software on infrastructure the customer owns or rents, instead of on the vendor's shared platform. The customer keeps the machines, the data and the bill; the vendor keeps operating the software.

CLOUD Act

The US CLOUD Act (Clarifying Lawful Overseas Use of Data Act, 2018) lets US authorities require providers subject to US jurisdiction to disclose data in their possession, custody or control, wherever in the world that data is stored.

Data residency

Data residency is the geographic location where data is stored and processed, usually set by law, contract or internal policy. It covers every copy of the data, including backups and logs, not only the main database.

Data sovereignty

Data sovereignty is the principle that data is subject to the laws of the country where it is held and of the countries whose laws bind the companies that operate it, and that its owner keeps control over who accesses it, where it goes and how it leaves.

Exit strategy

An exit strategy is a documented, tested plan for leaving a software or cloud provider: where the service moves, how the data comes out, who does what and how long it takes, so that leaving is possible without disrupting the business.

Model Context Protocol (MCP)

The Model Context Protocol is an open standard that lets an AI assistant discover and call tools in other systems, such as searching a wiki or querying a database, through a common interface called an MCP server.

nLPD (revised FADP)

The nLPD is the revised Swiss Federal Act on Data Protection (FADP, nDSG in German), in force since 1 September 2023. It sets the rules for processing personal data in Switzerland and is supervised by the FDPIC.

Recovery point objective (RPO)

The recovery point objective is the maximum amount of data, measured in time, that an organisation accepts to lose after an incident. An RPO of 24 hours means a restore may bring back the data as it stood up to a day earlier.

Recovery time objective (RTO)

The recovery time objective is the maximum time a system may stay unavailable after an incident before the disruption becomes unacceptable. It sets how quickly a service has to be restored and running again.

Source-available software

Source-available software publishes its source code for anyone to read, but under a licence that restricts some uses, such as offering it as a competing service. It is not open source in the sense of the Open Source Initiative definition.

Sub-processor

A sub-processor is a company that a processor engages to carry out part of the processing of personal data on a controller's behalf, such as hosting, email delivery or error reporting. The controller must authorise it in advance.

Vendor lock-in

Vendor lock-in is a dependency on one provider that makes switching costly or impractical, because of proprietary data formats, closed APIs, contract terms, integrations or skills that only work with that provider.

Zero-trust network access (ZTNA)

Zero-trust network access grants each person or device access to specific applications based on verified identity and policy, instead of trusting anything that sits inside a network perimeter. Nothing is reachable until a policy allows it.

Tell us what you need to run.

Thirty minutes with an engineer, a written plan and a fixed price for the first workload.