Security & data protection
InfoSec & Compliance.
How we secure data, access and decisions — so procurement and compliance teams can give the green light without reservation.
For institutional owners, pension funds and property managers, security is not a feature but a precondition. That is why we treat data protection, information security and traceability as part of the product, not as something bolted on afterwards.
Hosting & data location
| Server location | High-security data centers for regulated companies in Switzerland and the EU |
| Hosting model | Tenant-separated, logically isolated environments per customer |
| Data sovereignty | No data storage outside the EU or Switzerland without a contractual basis |
Encryption
- In transit: TLS 1.2+ for every connection.
- At rest: AES-256 encryption at database and backup level.
Access control
- Role-based access control (RBAC) following the least-privilege principle.
- Multi-factor authentication for administrative access.
- Logging of security-relevant events and access.
Availability, backup & recovery
- Regular encrypted backups with defined recovery objectives (RPO/RTO).
- Round-the-clock system monitoring.
Secure development
- Code reviews, separate development, test and production environments.
- Regular vulnerability scans and periodic penetration tests by external specialists.
Argued Intelligence: decisions you can trace
Our AI-supported pricing and matching decisions follow transparent, rule-based logic with a human-in-the-loop approach. No black box. Every recommendation can be explained and checked at any time — a compliance advantage that matters especially to institutional stakeholders.
Data protection compliance
- Processing in line with the GDPR and the Swiss FADP. Further information is set out in the privacy policy.
- Data processing agreements (DPAs) and a list of sub-processors on request.
Contact for security matters
Please send security reports and inquiries from procurement and compliance teams to security@beyonity.com.