A Swiss company, under Swiss law
Pilae SA is incorporated in Lausanne, Switzerland, and has no US parent and no US subsidiary. Your contract is with that Swiss company, governed by Swiss law. Your data protection terms follow the Swiss data protection act, with the GDPR alongside where it applies. See nLPD compliance and GDPR.
The US CLOUD Act lets US authorities require providers under US jurisdiction to produce data in their possession, custody or control, wherever it is stored. That is why the owner of the operator matters as much as the location of the server. A Swiss datacentre run by a US company can still be reached through its US parent. A foreign authority that wants data held by a Swiss company normally goes through international legal assistance handled by the Swiss authorities, and art. 271 of the Swiss Criminal Code restricts acts on behalf of a foreign state on Swiss soil without authorisation.
Server location is only half the answer
Your apps run in Pilae Cloud in any of 12 regions, six of them in Switzerland and the EU, or on your own premises. The region is yours to choose, per app, and your contract names it. The datacentres are ISO 27001-certified, and in Swiss and EU regions they are run by European datacentre operators, outside US jurisdiction.
The server location still matters. A workload placed in a US region, Ashburn or Hillsboro, is stored in the US and subject to US law on data held there, whoever operates it. To keep data under Swiss or EU law, choose Zurich or an EU region. See data residency and regions.
No operator can promise that no court anywhere will ever ask for anything. What we can do is keep the number of companies able to reach your data small, name each one, and keep US-controlled ones out of the path when you ask.
Where US exposure can come back
We list these openly, because a buyer who finds them later stops trusting the rest of the page:
- The public edge, which also sends our email, runs on a US-owned network provider. Traffic to an app you publish through the edge passes through it. Apps that answer only on the private network never touch it.
- Error reporting from our services can go to a US-owned service in its EU region. For your deployment it can be disabled or replaced with a self-hosted instance.
- External AI models are reached only if you enable them. Otherwise AI runs on a model you host. See private AI.
- Services you choose yourself. Signing in through Microsoft Entra ID puts identity data with a US provider; Keycloak keeps it in your deployment. A workflow in n8n that calls a US SaaS sends data to that SaaS, and its jurisdiction comes with it. The Pilae Agent records these connections so you can see them.
How to keep it out
For the strictest requirements, your apps answer only on the private mesh, there is no public edge, error reporting stays in-house, sign-in runs on Keycloak and every model runs inside your perimeter. At the far end, an on-premises or air-gapped deployment removes the internet path altogether. For banks and insurers, see FINMA outsourcing. To plan it for your organisation, talk to us.