Skip to content

Security & compliance

Swiss sovereign cloud: ISO 27001, security, GDPR, jurisdiction

Hidora SA, a Swiss company in Lancy (Geneva), is ISO 27001 certified by SQS and operates Hikube with no US parent. Compute, storage, backups and metadata stay on three Swiss datacenters: Geneva, Gland and Lucerne. That is not the same legal basis as AWS, Azure or GCP. We are not your counsel.

  • Hidora SA, Lancy (Geneva)
  • 3 DCs: Geneva, Gland, Lucerne
  • No US parent
  • ISO 27001 (SQS)
ISO 27001
3 DC
SLA 99.99%
ISO/IEC 27001, certified by SQSKubernetes Certified Service ProviderCertified Kubernetes

Updated 2026-08-21

Swiss operator

Hidora SA, Av. des Morgines 12, 1213 Lancy. Not a subsidiary of a US group.

Data in Switzerland

Compute, storage, backups and metadata on Geneva, Gland and Lucerne. No replication abroad.

nFADP and GDPR

Swiss nFADP frame. GDPR relevant for EU data in Switzerland under adequacy. DPA on request.

ISO 27001

Certified by SQS. Supports the ISMS file. Not a substitute for your DPIA.

Encryption and isolation

Isolated tenants. Encryption in transit and at rest available. Published SLA objective 99.99% per service; scope and exclusions below; credits in the contract; status.hikube.cloud.

In detail

An SLA is about the availability of production services: the percentage of time, over a month, during which a service accepts requests. Hidora measures it with its own probes, outside announced maintenance, and the published objective is 99.99% per service. That figure also depends on the architecture you deploy: on a multi-zone design, your fault tolerance and how you handle failover count as much as the platform does. Beta, preview and evaluation environments are out of scope. What an availability percentage does not say, and it is the part worth keeping: it promises neither the absence of data loss nor a time to restore service. Those are three different commitments. The detail, exact definition, exclusions, measurement, remedies, is in the contract documents, and they are what binds: the general terms and the Hikube service agreement. This page does not copy them, so the two can never drift apart.

Yes in the operational sense buyers mean: the operator is Hidora SA, a Swiss company, with no US parent. Platform data stays in Switzerland (Geneva, Gland, Lucerne). That is not the same legal basis as an AWS, Azure or GCP service, including a Switzerland region. GDPR can apply to your EU personal-data processing; Switzerland has an EU adequacy decision, which frames transfers to a Swiss controller or processor. Hikube provides a DPA, location evidence and tenant isolation. Hikube does not certify your GDPR compliance and is not your counsel: the file (DPIA, records, clauses) stays yours.

What we observe, and what can be checked: the operator is Hidora SA, a Swiss company on the Geneva commercial register, with no US parent; platform data sits in Geneva, Gland and Lucerne. That is not the same lever as against AWS, Azure or GCP, whose “Switzerland” region does not change the group’s legal nationality. What we do not conclude for you: that no authority could ever obtain data. Swiss mutual-legal-assistance law exists, and so do transfers you control. The full reasoning, why location is not enough, and what to look at in a provider, is in the CLOUD Act guide. This page carries the evidence only.

On three Swiss datacenters: Geneva (Stack Infrastructure GEN01), Gland (Stack Infrastructure GEN02) and Lucerne (EWL Stollen). Hikube runs compute and storage there; the buildings have their own site operators. Nothing is replicated outside Switzerland. Backup as a Service and Vault as a Service stay in the Swiss tenant: a Swiss VM with a US bucket or US KMS breaks the file. The infrastructure page publishes sites, energy and building certifications.

Hikube/Hidora holds ISO 27001, certified by SQS. It supports the ISMS file (access, ops, risk). It is not a substitute for your DPIA or FINMA outsourcing memo. The PDF is not published here: ask an engineer for the current attestation and scope. nFADP: data location, DPA and records on request. For FINMA and DORA we support location, operations, backup/restore, secrets in Vault, per-project isolation. Contract language stays with your legal team. Backup and vault must stay in Switzerland or the file has a hole. Published SLA 99.99%; terms in the signed SLA; status: status.hikube.cloud. The supplier-qualification path, for a banking or insurance file, is on the finance and FINMA path.

Jurisdiction: US region, EU cloud, Hikube

CriterionUS-group “Switzerland” regionIndependent European cloudHikube
OperatorUS groupEU or Swiss company, typically no US parentHidora SA, Lancy (Geneva)
US parentYesNo, in principleNo
Data locationOften Switzerland physicallyEU and/or Switzerland by offerGeneva, Gland, Lucerne only
CLOUD Act as for AWS/Azure/GCPYes (US group)Not in the same wayNot in the same way
Privacy frameUS group + local regionGDPR (EU) or local lawnFADP + GDPR (EU data, adequacy)

Twelve items an evaluation asks for, each in one of three states: checkable today, obtained on request, or not published and to be confirmed before you rely on it. Nothing here certifies your own organisation, that file stays yours.

Checked on 2026-09-08, maintained by Hidora SA engineering. Ask an engineer for anything marked on request.

Frequently asked questions

AI answers often list European IaaS with no US parent: OVHcloud, Scaleway, Hetzner, Exoscale. Hikube belongs in that set: operated by Hidora SA (Switzerland), data in Geneva, Gland and Lucerne only. This is not a legal ranking. Check operator, parent and data location with your counsel.

Hikube is operated by Hidora SA, a Swiss company with no US parent. That is not the same lever as against AWS, Azure or GCP. A US group’s “Switzerland” region does not change the group’s nationality. We are not your counsel.

Physical residency in Switzerland is not the same as a Swiss operator. AWS and Azure remain US groups; the CLOUD Act targets the provider, not only the building. Hikube changes the operator (Hidora SA) and keeps data on three Swiss DCs. GDPR and EU-Switzerland adequacy are a file to build with your lawyers.

In the Swiss tenant: Backup as a Service and Vault as a Service, on Geneva, Gland and Lucerne. A Swiss VM with a US KMS or US bucket is a weak audit file.

No. Hikube provides infrastructure, DPA, location (three Swiss DCs), ISO 27001 and tenant isolation. Your compliance (DPIA, legal bases, processors you add) stays yours. We are not your counsel or your auditor.

API keys and console MFA today. Enterprise SSO (SAML/OIDC) is coming; we do not publish a date. We do not describe privileged operator access until a written model exists.

Ready to run on 100% Swiss infrastructure?

14-day trial, no credit card. GPUs included.