Security and confidentiality

What protects your files — named, explained, verifiable

Many promise "hosted in Switzerland" without naming anything. We name the operator, the models and the encryption — so your counsel can verify instead of taking our word for it.


The principle, in one sentence

Your work stays under your control, end to end

LEMIA is software that runs on your own computer. The AI work is entrusted, without exception, to a Swiss operator; the software publisher never sees your texts; and nothing is sent unless you have said yes, while every change to your files can be undone. Every measure below is simply a concrete way of keeping those three commitments.

The measures, in plain words

What each protection does

Each card describes a protection that LEMIA is designed to provide — a best-efforts obligation, not a promise of results. We start with what each one prevents; what makes it hold is named further down, in the technical detail.

Everything happens on your own computer

Your files never go off “into the publisher’s cloud”: the publisher neither hosts them nor reads them. To keep the software running, it sees only technical markers — the current step, a few counters — never your texts and never your documents.

The agents stay inside the folder you open

The AI can only open the working folder you entrust to it, and nothing beyond it. You can also mark folders as completely unreadable to it: it can neither open them nor even know what they contain.

Everything goes through Switzerland, by design

AI processing is entrusted to a Swiss operator, not subject to US law — for text as well as for your images and scanned documents. As for the tools the AI could use to reach a service abroad, they are switched off.

A buffer zone before your real files

The documents produced by the AI are first prepared in a buffer zone (a holding area), off to one side. No new document reaches your real files until you have approved it; only the ones you keep are copied across. Correcting a document that already exists, by contrast, applies straight away — and can still be undone.

Nothing is sent without your approval

No email is sent, no external action is triggered on your behalf. Every send is shown to you with its content in front of you, for your approval. Sending remains your decision, exactly as if you had written the message yourself.

Your access keys in an encrypted vault

The keys that give access to the AI are kept in an encrypted vault on your machine. They are never exported, never displayed in plain text, never sent to the publisher.

Encrypted logs that stay with you

LEMIA keeps a technical record of its actions so that you can check what happened. That log is encrypted on your machine and never leaves it. What reaches the publisher is limited to technical metadata (counters, durations, statuses): no content and no file names appear in it.

Protection in several layers

Security does not rest on a single setting someone could forget to switch on. If one protection weakens, another blocks in its place. And when in doubt, the system closes by default rather than opens.

In one diagram

Several layers between the world and your files

The measures above interlock: to reach your files, every one of these layers would have to be crossed, one after the other.

Your computer — encrypted

Working perimeter

Buffer zone

Your approval

Your files

The buffer zone

Two possible outcomes — only one leads to your files

The new documents the agents produce wait in the buffer zone. From there, only two outcomes: you approve, and the result is written to your files; you refuse, and it is written nowhere. Your decision is the only route by which a new document reaches you.

A document that already exists, which you ask to have corrected, renamed or deleted, does not go that way: the operation applies straight away, to the very object you designated. What protects you there is not the wait but the way back: a copy of the original is set aside before any change, and if that copy cannot be made, the write is refused.

The named detail

What we use, precisely

Each line below names what we use — in the open, and with its limits: enough to check, point by point, every promise this page makes.

What is at stakeWhat we use
AI processing Infomaniak (INFOMANIAK NETWORK SA, Geneva, Switzerland) — a Swiss operator, not subject to US law
Models Ministral-3, Mistral-Small-4, Qwen3.5 (122B and 397B), Kimi-K2.6 and Nemotron — open-weight models, served in Switzerland, selected according to the task
Your files they stay on your own computer; only the excerpts required for the requested task are sent to the Swiss operator
Key vault AES-256-GCM encryption, with a 256-bit key kept on your machine and protected by DPAPI (Windows); never displayed in clear text, never exported, never sent to the publisher
Processing log encrypted at rest on your machine. If encryption is unavailable, LEMIA refuses to write the log rather than write it in clear text
What reaches the publisher technical markers only — steps, counters, durations, verdicts; the detail is just below
The AI’s web tools switched off by default: the AI cannot query a service located outside Switzerland unless you enable the optional web mode (globe button, disclaimer to accept) — the AI is then instructed never to disclose anything sensitive in its queries, and enabling it is your responsibility
Forbidden folders a red list that you maintain, on your working folder: you can make folders completely unreadable to the AI
Register and logging register of activities (art. 12 nFADP) and logging (art. 4 DPO), kept for at least one year, exportable as a dated file

The limit, since it has to be said. DPAPI protection of the vault applies within the perimeter of your Windows account: it puts your keys beyond the reach of another user of the machine and of a copy of the disk, but not of a program already running under your own session. This is the limit of any desktop software; we would rather write it than leave it out.

What reaches the publisher

An allowlist, closed by default

For the licence to work, a few technical markers leave your computer. They do not go through a filter that removes what is forbidden — it is the opposite: only explicitly allowed fields pass, and any unforeseen field is rejected. Automated tests fail if content crosses that boundary, and the separation is re-checked on every change to the software.

run     4f2a…             step     3 / 5
status  done              tokens   1,240 in / 380 out
time    12.4 s            verdict  accepted

That is what we see. What never appears in it: your texts, your instructions, the content produced, and even the names of your files.

Three common confusions

What looks alike, and is not equivalent

The vocabulary of confidentiality is now shared by the whole market. Three distinctions nonetheless decide what actually protects you. Put them to any vendor — including us.

Locating is not leaving a jurisdiction

A server located in Switzerland but operated by a company subject to US law remains within the scope of that law. The right question is therefore not “where are the machines”, but who operates them, and under which law. Ours is a Swiss operator, named above. We develop this point just below.

A contractual undertaking is not an architectural property

“Your data does not train the models” is almost always a contract clause — ours included, and we say so: that undertaking cascades by contract up to the Swiss operator. What is architectural is who can technically read: the software runs on your own computer, and the publisher does not receive your content.

Encrypting your storage is not holding the access key

Bringing your own encryption key protects files at rest at a provider who nonetheless continues to run the processing. Here, the key that opens access to the model is yours, in your vault, on your machine: it is your account that calls the AI, not ours.

Sovereignty

Hosting in Switzerland is not enough. Sovereignty is

For a professional bound by secrecy (Art. 321 of the Swiss Criminal Code), the real test is not where the servers sit, but who can be legally compelled to grant access to them. Hosting data in Switzerland answers a data-protection question. But hosting it also means entrusting it to a provider. Professional secrecy then asks another one: can that provider be compelled to open your files? A “Swiss region” operated by a group subject to foreign law remains exposed.

“My data is in a Swiss region.”

An extraterritorial access law — the US CLOUD Act (18 U.S.C. § 2713), for instance — targets the operator subject to US law and compels it to produce the data “regardless of whether… located within or outside of the United States” — hence even in a “Swiss region”. What matters is not the flag flying over the data center, but the law the operator is subject to.

A Swiss operator no foreign authority can compel

Your AI processing goes, without exception, through a Swiss operator with no foreign parent company, on its own servers. It therefore stays beyond the reach of any extraterritorial right of access.

Everything else runs on your workstation

The software works on your own machine: your content is never read by the publisher, and nothing is sent without your approval, and every write can be undone. Those are the measures described higher up on this page.

What we do not claim. The exact threshold at which a foreign cloud becomes inadmissible has not been settled by the courts: that assessment is a matter for your own professional judgement. Our argument rests on the legal risk of compulsion, not on proven cases.

  1. Extraterritorial access — CLOUD Act, 18 U.S.C. § 2713: compels an operator subject to US law to produce the data “regardless of whether… located within or outside of the United States” — the obligation applies even in a “Swiss region”. law.cornell.edu/uscode/text/18/2713 · US federal law

The risk of foreign access is legally established, but no case has been publicly documented involving Swiss data (sealed proceedings). The wider picture of professional secrecy (Art. 321 of the Swiss Criminal Code, the revised Federal Act on Data Protection) is set out below.

The law that binds you, by profession

Every profession has its secret — and its article of law

The core of the law that binds you often fits in a single article: Art. 321 of the Swiss Criminal Code punishes whoever unlawfully discloses a secret entrusted to them in the practice of their profession — an offence prosecuted on complaint, punishable by a custodial sentence of up to three years or a monetary penalty. It covers a closed circle of professions; other regimes add to it or extend it. A reassuring point: auxiliaries are themselves bound by secrecy (Art. 321 para. 1 of the Swiss Criminal Code) — that is what makes their access lawful — and disclosure remains non-punishable with the consent of the person concerned or the written authorisation of the superior authority (para. 2).

Doctors and healthcare professions

Medical secrecy falls under Art. 321 of the Swiss Criminal Code, complemented by Art. 40 of the Medical Professions Act (MedPA/LPMéd) and cantonal law. Health, diagnoses, patient records: these are, in addition, sensitive data within the meaning of the new Federal Act on Data Protection (nFADP) — Art. 5 FADP.

Lawyers

On top of the secrecy of Art. 321 of the Swiss Criminal Code comes Art. 13 of the Lawyers Act (LLCA): a reinforced secrecy, covering all matters entrusted, unlimited in time and enforceable against third parties.

Notaries

Notaries are covered by Art. 321 of the Swiss Criminal Code and by cantonal law (for instance, in Geneva, Art. 7 of the Notarial Act, LNot). The exact scope varies from canton to canton.

Public sector and administration

Civil servants and public officials — civil registry, disability insurance offices, land registry, tax assessment — are bound by official secrecy (Art. 320 of the Swiss Criminal Code). Lifting it requires the written consent of the superior authority.

Banking and audit

Banking secrecy (Art. 47 of the Banking Act, BankA/LB) is a criminal-law regime; the licensed audit body is bound by the secrecy of Art. 730b of the Swiss Code of Obligations: licensed audit is the only fiduciary activity backed by a criminal-law secrecy duty (Art. 321 of the Swiss Criminal Code).

“Pure” fiduciaries (outside Art. 321)

Fiduciaries (Swiss accounting & trust firms) not covered by Art. 321 remain bound by business secrecy (Art. 162 of the Swiss Criminal Code / Art. 6 of the Unfair Competition Act, UCA/LCD) and by the fallback regime of the FADP (Art. 62). The duty of discretion exists; only its legal basis changes.

Two points to remember: the sanction is a criminal one and is triggered on complaint; and your auxiliaries do not put you at fault — they are themselves bound by secrecy (Art. 321 para. 1 of the Swiss Criminal Code), and disclosure remains non-punishable with the consent of the person concerned or the written authorisation of the superior authority (para. 2).

Data protection, on top

The FADP adds to secrecy — it does not replace it

On top of professional secrecy sits a second, cumulative regime: the FADP. It applies to any personal data, and its requirements bind you whether or not you fall under Art. 321.

  • Mere routing is already “processing” (Art. 5 FADP) — even without reading. Passing a piece of data through a third-party service means processing it; the same article defines sensitive data (health, intimate sphere, genetic or biometric data, criminal proceedings and sanctions…).
  • Art. 8 FADP requires data security: that is the obligation answered by the measures described higher up — encryption, compartmentalisation, logging.
  • Art. 9 FADP governs processing entrusted to a third party, under instruction and subject to security safeguards: this is the basis of the data processing agreement (DPA). Since access to the AI models is made using your firm’s own access keys, that agreement is entered into directly between your firm and the AI provider — the Publisher is not a party to it (see the Terms of Use, art. 5.1 and 11.2, and the privacy policy, §3).
  • Art. 21 FADP governs decisions taken “exclusively by automated means”: you are the one who decides — you review every output before it has any effect on anyone else, and the software triggers no external action without your approval. That classification is thereby ruled out.
  • And above all: the fine (Art. 60 and 61 FADP) — up to CHF 250,000, imposed on the responsible natural person — and not on the company. The most concrete lever of the law that binds you.

If your firm or practice extends its activity into the European Union, the GDPR applies in addition (processing on behalf of a controller, Art. 28; impact assessment, Art. 35).

What LEMIA does with it, in one sentence: your content is processed in Switzerland, by design and without exception; it is never read by the publisher, and every output is reviewed and approved by you before anything is sent, and every write to your files can be undone. Sovereign processing answers the question of transfers abroad; human approval answers the question of automated decision-making; and the fact that your content is never read, together with the data processing agreement, answers professional secrecy and the FADP.

Verifiable guarantees

Every promise has its clause, and its proof

We do not ask you to take our word for it: every commitment below is written into our Terms of Use — and therefore enforceable — and matches a mechanism in the product that you can see for yourself during a demonstration.

Content never read by the publisher

Committed: Terms of Use Art. 4.2 and 11.2 — the publisher receives neither your documents nor the content produced. Verifiable: the software runs on your own computer; only technical markers (steps, counters) exist on the publisher’s side, never your texts.

Swiss operator, written into the architecture

Committed: Terms of Use Art. 4.3 — the elements needed for processing are transmitted only to the Swiss operator. Verifiable: no setting and no menu lets your data be sent to an AI outside Switzerland — the restriction is built into the structure of the software, not into an option. The only other possibility is a model run locally on your own computer, offline, with no network traffic at all.

Human approval, and a way back

Committed: Terms of Use Art. 4.4 — no send without your explicit approval; documents produced wait for your approval; changes to a document that already exists apply straight away and remain reversible. Verifiable: ask for an amount to be corrected in one of your own documents — the correction applies, and “Undo” reverses it. Try a send too: nothing goes out on its own.

Forbidden folders, genuinely unreadable

Committed: a documented product feature (the Compliance space). Verifiable: put a folder on the red list, then ask the AI to read it — it can neither open it nor list its contents.

Register and compliance file

Committed: processing logs (Art. 4 OPDo, the Swiss data protection ordinance) kept for at least one year. Verifiable: the Compliance space exports a dated compliance file in one click, ready to be presented to the FDPIC (the Swiss data protection authority) or to your legal counsel.

Transparency about AI

Committed: Terms of Use Art. 8 — content is generated by AI systems, may contain errors and does not constitute professional advice. Verifiable: the information appears in the interface itself, not only in the contract.

What we do not claim

Trust is also earned by stating the limits

Our measures are best-efforts obligations, not a guarantee of invulnerability: no system is “100% tamper-proof”. Legal compliance also depends on the data processing agreement and on your own situation: you remain the data controller within the meaning of the FADP, and your external sends remain your decision. We do not claim to be “compliant by design”.

A question about these measures?

We are glad to answer, in detail, any question that touches on the protection of your files.