Private IT and AI for hospitals, clinics and life sciences in Switzerland

Hospitals, clinics, research groups and pharma teams run collaboration, research databases and private AI on their own servers or on dedicated machines in Switzerland, with patient and study data kept under their control.

Talk to our teamBook a 30-minute briefing

Deployment
Your premises, Pilae Cloud in Zurich, or air-gapped
Data class
Health data, treated as sensitive personal data
Private AI
Open models on your machines, prompts stay there
Record
Every change and administrative access, exportable

Health data needs an operator that knows what it is holding

Patient records, study data and lab results are sensitive personal data under the Swiss Federal Act on Data Protection. Where they sit, who can reach them and what is recorded about each access are questions your data protection officer, your ethics committee and your auditors will ask.

On your premises

Apps run on servers in your own hospital or research building, next to the systems they work with, under your physical and network controls.

Or in Switzerland

Dedicated machines in Zurich, hosted in ISO 27001-certified datacentres. The contract names Switzerland as the location for your apps, data and backups.

Private AI for clinical and research work

Staff summarise, draft and search with open models on your own hardware. No prompt, report or dataset goes to a public AI service.

Closed to the internet

Apps answer only on a private mesh network. One hardened gate on port 443 is the single way in, and you decide who may pass it.

Access your auditors can read

Each change, approval and administrative session is written to an audit log your security office and data protection officer can export.

Backups tested every month

Daily encrypted backups, stored offsite in the country you choose, with a restore test every month recorded in the console.

Sensitive health data, kept where you decide

Patient records, study datasets and lab results are sensitive personal data under the nLPD. The first question is where they sit. Pilae runs your apps on your premises, on dedicated machines in Zurich, or air-gapped, and the contract names each location. Backups follow the same rule: stored offsite in the country you choose, tested every month. The data residency page explains where each copy lives.

Private AI for clinical and research teams

Clinicians want help summarising reports and drafting letters. Researchers want to search papers and protocols. The documents they would paste into a public chatbot are exactly the ones that must not leave. We run private AI on your own hardware, with open models and Open WebUI as the interface. The same setup serves a hospital department or a research group.

Research databases and tools under the HRA

Research under the Human Research Act often works with coded data, and it needs project-level access and a record of who reached what. We operate PostgreSQL for study databases, Metabase for dashboards and Nextcloud for protocols and shared files, with single sign-on through Keycloak and roles per project.

Pharma and medtech teams that answer for every change

A validated system is only as good as its change record. The Pilae Agent plans every update, waits for your approval, applies it in your window after a verified backup and records each step. Your quality team gets the plan, the approval and the result for every change, exportable to your own systems. The security page explains how access and logging work.

Talk to us

Contact us to discuss your data classes and constraints.

How we start with a hospital or research group

  1. Data classification

    With your IT, data protection and research teams we map each app to the data it will hold: patient data, coded research data, or neither.

  2. Placement decision

    Together we decide what runs on your premises, what runs in Zurich and what stays air-gapped.

  3. Fixed-price onboarding

    We install the apps, connect Keycloak or Entra ID with multi-factor authentication and move your data off the tools you are leaving.

  4. Acceptance

    Your team tests each app, its roles and its access rules before any real data goes in.

  5. Managed operations

    The Pilae Agent plans each update and waits for your approval. Monitoring alerts reach Pilae engineers around the clock.

What your contract includes

Data location
Named per app: your premises or Switzerland. Apps, data and backups stay there unless you agree otherwise in writing.
Data processing
A data processing agreement under the nLPD, with the sub-processor list and technical measures for sensitive data.
Access
Named Pilae engineers, over the private network, under access rules you set. Every session is recorded.
Confidentiality
Confidentiality obligations binding Pilae and each engineer, written with medical professional secrecy under art. 321 SCC in mind.
Availability
99.9% monthly availability commitment with service credits, in every plan.
Exit
A full export of data and configuration in open formats, at any time and at the end of the contract.

The apps behind it

Questions

Is health data treated differently under the nLPD?

Yes. The Swiss Federal Act on Data Protection classes data on health as sensitive personal data, which raises the bar for consent, disclosure and security measures. Your contract includes a data processing agreement that covers sensitive data and the hosting location for each app. Public hospitals usually fall under cantonal data protection law instead, and cantonal health laws may add rules. We work with your data protection officer on whichever applies.

Can research data under the Human Research Act run on Pilae?

Yes. Research under the Human Research Act (HRA) often works with coded data and needs access limited to the project team and a record of who reached the data. We run the research database and tools on your premises or in Switzerland, with roles per project and every administrative access in the audit log. The approval of your ethics committee and the coding of the data remain with your research team.

Can clinicians use AI without sending patient data to a public service?

Yes. Open WebUI runs on your machines with open models hosted there. Prompts, uploaded documents and answers stay inside your environment. The optional connection to an external model through an AI gateway stays off unless you decide to enable it.

Where are backups of patient and study data kept?

Backups run daily, are encrypted and are stored offsite in the country you choose, which for health data is usually Switzerland. A restore test runs every month and its result is recorded in the console. Retention follows your plan, and the recovery point and recovery time objectives are written in the contract.

Does Pilae replace our hospital information system?

No. We operate the open-source apps around it: file sharing, internal documentation, research databases, dashboards, workflow automation and private AI. They connect to your existing systems through their standard interfaces, under access rules you set.

Does Pilae hold a health-sector certification?

No. Our operations are built to ISO 27001 controls, and Pilae Cloud machines are hosted in ISO 27001-certified datacentres. For a pharma team validating a system, the audit log gives a complete change record: plan, approval, result and rollback for every change.

Related

Discuss your data classes with an engineer.

Thirty minutes with your IT and data protection teams. We come back with a placement proposal for each app and each class of data.