SavianoSwitzerland
Sovereign workspace

A Swiss office suite, built so that we cannot read your documents.

Mail, messaging, files, video calls, documents, vault and private artificial intelligence. A complete working environment, hosted in Switzerland, encrypted on your own devices, with keys that stay with you.

In preparation. First access is granted in waves, to organisations willing to be involved in shaping the product.

Most law firms, trustees, family offices and executive teams work on American suites today. Their most sensitive documents, acquisition agreements, litigation files, board memos, accounting records, sit in an infrastructure whose real location, keys and subcontractors they do not control.

We are building the alternative we wanted for our own operations: a Swiss working suite where the provider does not hold the technical means to read what you put in it.

This is not a promise of discretion. It is an architectural choice, and it can be verified.

The building blocks

Seven services, one environment.

Each block replaces a service you already use. They share one identity, one directory, one security policy and one administration console, which avoids the patchwork of isolated tools that makes sovereignty unmanageable day to day.

Mail

Gmail, Outlook

Mailboxes on your own domain, strong encryption, and end to end encryption between users of the environment. Existing archives are imported.

Messaging

WhatsApp, Teams, Slack

One to one and group conversations encrypted end to end, on desktop and mobile, with controlled retention and scheduled deletion.

Files

Google Drive, Dropbox, OneDrive

Sharing and synchronisation, with encryption performed on the device before anything is sent. The server stores blocks it cannot open.

Video calls

Zoom, Google Meet

Meetings encrypted end to end, no account required for external guests, with waiting rooms and recording disabled by default.

Documents

Google Docs, Microsoft 365

Real time collaborative writing and spreadsheets, in the browser, on documents encrypted from the workstation.

Vault

1Password, shared folders

A zero knowledge compartment for the most sensitive material: passwords, articles of association, shareholder agreements, internal investigation files. Named access, logged and revocable.

Artificial intelligence

ChatGPT, Copilot

Search, summarisation, drafting and contract analysis over your own documents, with models running on infrastructure we operate in Switzerland. Your material is never sent to a third party interface.

Architecture

Encryption happens before departure, not after arrival.

The difference between a service hosted in Switzerland and a zero knowledge service comes down to one detail: where the key is at the moment the document is encrypted. With most providers the server encrypts, so the server can decrypt. Here the device encrypts, and the server only ever receives an opaque block.

01

On your device

The document is encrypted in the application or in the browser, with a key derived from your credentials and never transmitted in the clear.

02

On the network

What travels is already unreadable. The transport layer becomes an extra safeguard rather than the main one.

03

On our Swiss servers

Storage, backups and logs stay in Switzerland. The content there is an encrypted block whose key we do not hold.

04

On retrieval

Only an authorised device in your organisation reassembles the document. Our system administrator sees an identifier and a size.

Legal framing

What we promise, and what we will never promise.

Legal framing

Many providers write that they will never hand over your data. The sentence sells well and is legally false. A Swiss company remains subject to Swiss law, and the federal act on the surveillance of post and telecommunications can require certain providers to hand over the data they hold, and to remove encryption they applied themselves.

Our commitment is therefore of a different kind. We design the service so that the means of reading your sensitive content are not in our hands. A valid order does not conjure up a key we never held.

Swiss jurisdiction adds a real layer without amounting to immunity. A foreign authority cannot carry out a coercive act directly on Swiss soil: it goes through mutual legal assistance, and Swiss authorities examine the request, check proportionality and reject fishing expeditions. Switzerland does cooperate, and can order production when the conditions are met.

The European regulation known as e-Evidence, applicable since 18 August 2026, also allows authorities of a member state to address production or preservation orders to providers offering services in the Union, including providers not established there. Being Swiss therefore does not put anyone out of reach. That is precisely why the protection has to be cryptographic before it is legal.

  • We examine the validity and the scope of every request, and challenge those that are legally questionable.
  • We hand over only what the law requires, and nothing beyond it.
  • We publish transparency figures as far as the law allows.
  • We document what we actually hold for each service, so you know in advance what an order could reach.
  • Switzerland benefits from a European Union adequacy decision: a European company can use a Swiss provider without special contractual arrangements.
Tiers

Three levels, depending on what you have to protect.

The first suits a company that wants to leave the American suites without upending its habits. The third is for organisations where a single document can be worth a lawsuit. The tiers are cumulative.

01

Swiss

Leave the American suites without changing the way people work.

  • Hosting, backups and logs in Switzerland
  • Seven blocks under a single identity
  • Encryption at rest and in transit
  • Migration from Google Workspace or Microsoft 365
  • No advertising, no profiling, minimal telemetry
02

Zero knowledge

The provider no longer holds the means to read your content.

  • Encryption performed on the device for files, vault and messaging
  • Keys derived on the workstation, never transmitted in the clear
  • Metadata reduced to what the service technically needs
  • Named access log, readable by your own administrator
  • A written inventory of what we hold, service by service
03

Sovereign

Your keys, your hardware, your model.

  • Master keys held by you, up to a dedicated hardware module
  • Dedicated rather than shared infrastructure
  • Private artificial intelligence over your documents, with no third party egress
  • Endpoint and mobile management, access without implicit trust
  • Configuration audit and an annual sovereignty report

Artificial intelligence without giving up the documents

This is where the gap with the American suites becomes most concrete. An organisation holding two hundred thousand emails, contracts, invoices and client files has everything to gain from querying them in plain language. It has everything to lose by sending them to an interface whose retention and reuse it does not control.

We run the models on infrastructure we operate in Switzerland, and the search index stays inside your environment. The question asked and the documents consulted do not leave the perimeter.

  • Plain language search across mail and files
  • File summarisation and contract clause extraction
  • Assisted drafting from your own document templates
  • Consistency checks between accounting records and contracts
  • No training data taken from your content

Migration is the real project

Changing office suite is not a licence purchase, it is a move. Mail archives, shared calendars, files, access rights, secondary addresses and staff devices all have to follow without a service interruption.

We treat this phase as a project in its own right, with an inventory beforehand, a switch in waves and a period of parallel running. It is the same work we carry out on our own platforms, where an hour of mail downtime is paid for immediately.

  • Inventory of accounts, domains, aliases, groups and devices
  • Transfer of mail archives and calendars
  • Switch in waves, with parallel running
  • Short team training and documentation in three languages
  • Support through the first three months of operation
Frequent questions

What executives ask before signing.

The answers are deliberately direct, including where they do not favour the product.

Can a French prosecutor obtain our documents?

They cannot carry out a coercive act directly on Swiss soil. They must go through cooperation mechanisms, and Swiss authorities examine the request, check proportionality and reject fishing expeditions. Where the conditions are met, Switzerland cooperates and can order production. What we can then hand over is limited to what we hold, and on the zero knowledge tiers we do not hold the keys to your content.

Does e-Evidence put you out of reach?

No, and be wary of providers who claim otherwise. That regulation, applicable since 18 August 2026, also covers providers not established in the Union as soon as they offer services there. A Swiss address is not an exemption. The protection that matters is the one that holds even when an order is valid, which means the architecture.

Will you commit to never handing over our data?

No, and nobody serious should. A Swiss company is subject to Swiss law, which can require it to hand over what it holds and to remove encryption it applied itself. Our commitment is a different one: to deliberately reduce what we hold, and to document precisely what remains.

What exactly can you see of our activity?

On the zero knowledge blocks we see that objects exist, their size, their date and the accounts that access them. We see neither file names in the clear nor their contents. On the communication blocks, some routing metadata is technically necessary. We publish the list, service by service, rather than maintaining a convenient vagueness.

What happens if we lose our keys?

That is the honest cost of zero knowledge. We cannot recover content whose key we do not have. The design therefore includes recovery keys held by your organisation, split across several holders, and on the sovereign tier a dedicated hardware module. The loss procedure is part of onboarding, not an option.

Do we have to migrate everything at once?

No. Most organisations start with the vault and the files, where the risk is concentrated, then move mail once habits have settled. Parallel running is provided for during the transition.

Can the service be used from the European Union?

Yes. Switzerland benefits from a European Union adequacy decision, which lets a European company use a Swiss provider without a special contractual construction for the transfer.

When is it available?

The offering is in preparation and first access is granted in waves. Write to us describing your organisation, the number of seats and the services you use today: we reply with a realistic timeframe, or by telling you that your need would be better served elsewhere.


Ask for access to the first waves.

Describe your organisation, the number of seats and what you use today. We answer within two working days, including to say that it is not the right moment yet.

Write to us