Compliance for software vendors: answering your customers' questions about us

When you sell software to insurers, banks, hospitals or cantons, their compliance team reviews your hosting provider before they sign. The questions arrive as a list, they are always roughly the same eight, and one of them is the difficult one: can your provider grant audit rights to us?

This page answers all eight, so you can forward it instead of writing the answers yourself.

The eight questions

1. Where are your datacenters, physically?

Switzerland. VSHN operates no datacenters of its own and runs your services on Swiss infrastructure you choose: Cloudscale in Lupfig (AG) and Rümlang (ZH), Exoscale in Zurich (CH-DK-2) and Geneva (CH-GVA-2), or your own on-premises hardware. Data does not leave the country as part of normal operations.

2. Are you an independent Swiss company?

VSHN AG is a Swiss stock corporation headquartered in Zurich, founded in 2014, with over 50 employees. There is no foreign parent company and no foreign investor. Every shareholder is a Swiss citizen, on record in the commercial register of the canton of Zurich under CHE-275.566.226.

This is the answer behind the CLOUD Act question. US authorities can compel a company subject to US jurisdiction, which means a US parent, a US subsidiary or US operations. VSHN has none of the three.

3. Which subprocessors do you use?

For a typical engagement, one: the infrastructure provider you selected. The complete, current list is part of the data processing agreement, which means it is a contractual commitment rather than a marketing statement, and changes to it follow the notification process in that agreement.

4. Can you sign a DPA under Art. 9 of the Swiss FADP?

Yes. Our data processing agreement is published rather than negotiated from scratch, governed by Swiss law with Zurich as the place of jurisdiction. Annex 1 lists the technical and organizational measures, which is usually the annex your customer's data protection officer reads first.

5. Do you offer managed databases with high availability and point-in-time recovery?

Yes. Managed PostgreSQL runs as a primary with a replica and automatic failover, with point-in-time recovery and encryption at rest. Backup is part of the service. The same applies to the other services in the catalog, including Keycloak for customer identity and OpenBao for secrets.

6. Which tenant isolation model do you recommend?

For regulated data, a separate database instance per major customer, with schema isolation for the tenants underneath. Our reasoning, including what that choice costs, is on the multi-tenancy isolation guide on our PostgreSQL site.

7. Can services reach our customers' on-premises systems?

Yes. Some of your larger customers will refuse to put their data in your cloud database and will want your application to read from their own systems instead. Outbound connectivity is arranged per customer, either over defined egress addresses or a VPN tunnel, and the right shape depends on what their network team allows. This is worth a technical call rather than a checkbox.

8. Will you grant audit rights to our customers?

This is the question that decides deals, so here is the honest answer in three parts.

What is already covered. Most of what an auditor asks for is satisfied by evidence that exists before anyone asks. VSHN is ISO 27001 certified and produces an ISAE 3402 Type II report, which is an independent auditor's opinion on whether our controls were designed properly and actually operated over a defined period. Type II is the distinction that matters: it covers a period of real operation, not a snapshot. In practice this closes most of a due-diligence questionnaire without a site visit.

What is negotiated. Contractual audit rights for you and for your customer, including on-site audits, are agreed in the contract. We have done this before for customers under FINMA supervision, including cantonal banks through Finnova and Acrevis Bank. The clause is written for the specific engagement.

What we will not do. We will not tell you a clause is pre-approved before our legal team has read your customer's wording. A provider who promises that in a first email is telling you what you want to hear.

Book an Assessment

Why this is different when you are the vendor

Nothing on this page is a requirement of yours. Every item is inherited from a customer of yours, which changes what you need from a hosting provider.

You do not primarily need a platform that runs well. You need one that produces evidence: a certificate with the right scope, an audit report covering a period rather than a day, a published DPA your customer's lawyer can read without a meeting, and a provider willing to be named in your own outsourcing documentation.

That is a different purchase from buying capacity, and it is why the answers above are written to be forwarded rather than summarized.

What VSHN runs for you

One contract covering the whole stack: managed Kubernetes, PostgreSQL, Keycloak, object storage, secrets management and the platform underneath. One operations team, based in Switzerland, on call around the clock. Every component is upstream open source, so the exit path is a data export rather than a rewrite.

Book a call if you want the answers above checked against your customer's actual questionnaire.

Start with an architecture assessment

Tell us about your infrastructure and the services you need. We'll map out how the Application Catalog fits your environment and provide a custom proposal.

Book a free call

Or ask your question