CLOUD Act and jurisdiction: a Swiss operator with no US parent

Pilae SA is a Swiss company under Swiss law, with no US parent. We show you where US exposure can still enter a deployment and how your design keeps it out.

Talk to our teamRequest the security pack

Operator
Pilae SA, Lausanne, Switzerland
Ownership
Swiss company, no US parent or subsidiary
Governing law
Swiss law, Swiss courts
Hosting
Any of 12 Pilae Cloud regions, or your premises

Where jurisdiction is decided in a deployment

Jurisdiction follows the companies that can reach your data, not only the country the servers sit in. We map every one of them with you.

A Swiss operator

Pilae SA is incorporated in Lausanne and owned outside the United States. The company operating your apps is not a US company.

Infrastructure you place

Pilae Cloud runs on dedicated machines in ISO 27001-certified datacentres, run in Swiss and EU regions by European operators outside US jurisdiction, or on your own hardware.

Nothing added in silence

Your data processing agreement sets the terms for every party that processes your data. Nothing is added without notice, and you can object.

The US exposure we disclose

A few supporting services, such as our public edge, come from US companies. We tell you what each one touches and how to keep it off your data path.

Backups encrypted before they leave

Backups are encrypted on your machine before they are sent offsite, so the storage provider holds only data it cannot read.

Air-gapped when it must be

For the strictest cases your apps run on your premises with no internet connection. Updates come in through a transfer you approve.

A Swiss company, under Swiss law

Pilae SA is incorporated in Lausanne, Switzerland, and has no US parent and no US subsidiary. Your contract is with that Swiss company, governed by Swiss law. Your data protection terms follow the Swiss data protection act, with the GDPR alongside where it applies. See nLPD compliance and GDPR.

The US CLOUD Act lets US authorities require providers under US jurisdiction to produce data in their possession, custody or control, wherever it is stored. That is why the owner of the operator matters as much as the location of the server. A Swiss datacentre run by a US company can still be reached through its US parent. A foreign authority that wants data held by a Swiss company normally goes through international legal assistance handled by the Swiss authorities, and art. 271 of the Swiss Criminal Code restricts acts on behalf of a foreign state on Swiss soil without authorisation.

Server location is only half the answer

Your apps run in Pilae Cloud in any of 12 regions, six of them in Switzerland and the EU, or on your own premises. The region is yours to choose, per app, and your contract names it. The datacentres are ISO 27001-certified, and in Swiss and EU regions they are run by European datacentre operators, outside US jurisdiction.

The server location still matters. A workload placed in a US region, Ashburn or Hillsboro, is stored in the US and subject to US law on data held there, whoever operates it. To keep data under Swiss or EU law, choose Zurich or an EU region. See data residency and regions.

No operator can promise that no court anywhere will ever ask for anything. What we can do is keep the number of companies able to reach your data small, name each one, and keep US-controlled ones out of the path when you ask.

Where US exposure can come back

We list these openly, because a buyer who finds them later stops trusting the rest of the page:

  • The public edge, which also sends our email, runs on a US-owned network provider. Traffic to an app you publish through the edge passes through it. Apps that answer only on the private network never touch it.
  • Error reporting from our services can go to a US-owned service in its EU region. For your deployment it can be disabled or replaced with a self-hosted instance.
  • External AI models are reached only if you enable them. Otherwise AI runs on a model you host. See private AI.
  • Services you choose yourself. Signing in through Microsoft Entra ID puts identity data with a US provider; Keycloak keeps it in your deployment. A workflow in n8n that calls a US SaaS sends data to that SaaS, and its jurisdiction comes with it. The Pilae Agent records these connections so you can see them.

How to keep it out

For the strictest requirements, your apps answer only on the private mesh, there is no public edge, error reporting stays in-house, sign-in runs on Keycloak and every model runs inside your perimeter. At the far end, an on-premises or air-gapped deployment removes the internet path altogether. For banks and insurers, see FINMA outsourcing. To plan it for your organisation, talk to us.

How we keep US exposure out of your deployment

  1. Map the data path

    We list every app, every connection it makes and every provider that could see the traffic or the data.

  2. Remove what you do not need

    Public exposure through the edge, external error reporting and hosted AI models are switched off for your deployment where you ask.

  3. Replace with European or in-house options

    Private mesh access instead of a public edge, a model hosted in your perimeter instead of a US API.

  4. Write it into the contract

    The locations, the providers and the services left out are named in your contract and data processing agreement.

What your contract includes

Contracting party
Pilae SA, Rue de Bourg 27, 1003 Lausanne, Switzerland.
Governing law and forum
Swiss law, with the courts of Lausanne as the place of jurisdiction.
Sub-processors
Covered by your data processing agreement. Changes notified in advance, with a right to object.
Authority requests
We disclose customer data only where Swiss law obliges us, and tell you first unless the law forbids it.
Excluded services
US-controlled services you exclude are listed in your contract and stay off your deployment.

Questions

Does the US CLOUD Act apply to Pilae?

The CLOUD Act reaches providers subject to US jurisdiction, which can include non-US companies with enough ties to the United States. Pilae SA is a Swiss company with no US parent, no US subsidiary and no US office, and it operates under Swiss law. A foreign authority that wants data from a Swiss company normally goes through international legal assistance handled by the Swiss authorities.

Is Pilae Cloud hosted by a US provider?

No. Pilae Cloud runs on dedicated machines in ISO 27001-certified datacentres, and in Swiss and EU regions they are run by European datacentre operators, outside US jurisdiction. Six of the 12 regions are in Switzerland and the EU. If you place a workload in a US region, Ashburn or Hillsboro, it is stored in the US and subject to US law on data held there. You can also run everything on your own premises.

Where can US exposure still come in?

Through US companies in the data path. Our public edge and email delivery run on a US-owned network provider, and an external AI model is used only if you enable it. Services you choose yourself, such as Microsoft Entra ID for sign-in or a US SaaS in an n8n workflow, add their own exposure.

Can I keep every US company out of my deployment?

Yes. Your apps can answer only on the private mesh with no public edge, error reporting can be disabled or kept in-house, and AI can run on a model hosted in your perimeter. The services you exclude are written into your contract.

What happens if an authority asks Pilae for my data?

We disclose customer data only where Swiss law obliges us to. We tell you before we do, unless the law forbids it, and we disclose no more than the order requires.

Related

Map your data path with an engineer.

We go through your apps and their connections, name every provider that could see your data, and show you how to keep US companies out of it.