Your Client Data Belongs in Switzerland, Not on US Servers.
Generic AI tools process data on servers outside Switzerland, use customer data to improve their models, and provide no audit trail. For a law firm, this is a professional conduct issue. Whisperit is built to address this from the ground up.
The lawyer's data security problem
Bar association rules
Art. 13 LLCA and Art. 321 SCC impose a duty of confidentiality that extends to how client data is stored and processed, not just what lawyers say in conversation. Using a tool that shares client data with a US company may breach this duty.
GDPR and nFADP obligations
Swiss law firms processing personal data are subject to the nFADP. Those with EU clients are also subject to GDPR. Both require appropriate technical and organisational measures and documented data processing agreements.
The generic AI risk
Most general-purpose AI tools process data in the US, may use customer data to train models, and do not provide audit logs. These are not minor compliance gaps. They create real professional liability.
Why generic AI tools create professional risk
| Risk | Generic AI tools | Whisperit |
|---|---|---|
| Data processed on US servers | ⚠️ Common | ❌ Never |
| Used to train AI models | ⚠️ Often default | ❌ Never |
| Vendor access to content | ⚠️ Typically yes | ❌ Zero access |
| Audit trail for data access | ❌ Rare | ✅ Full logs |
| Compliant DPA available | ⚠️ Varies | ✅ Standard |
What to look for in a secure legal AI tool
Data residency: where is content processed and stored?
Encryption: in transit (TLS 1.3+) and at rest (AES-256)?
Vendor access: can the provider read your documents?
Model training: is your data used to train AI models?
Audit logs: is there a record of who accessed what?
Data processing agreement (DPA): is one available?
Breach notification: what is the response process?
Subprocessors: who else touches the data?
Whisperit's security architecture
Swiss hosting
Your documents, transcriptions and case data are stored on Swiss infrastructure in ISO 27001-certified data centres, under Swiss law and outside US CLOUD Act jurisdiction. Where the AI processing itself runs depends on the residency tier your firm is on, described next.
You choose where AI runs
Three residency tiers. Swiss Only routes every AI feature through a Swiss-hosted provider and never falls back elsewhere: if that provider is unavailable the request fails rather than rerouting. EU routes through an EU-based provider. Global adds an international fallback. The tier is set per tenant and does not change without your request.
End-to-end encryption
TLS 1.3 in transit, AES-256 at rest. The same standards used by major financial institutions and Swiss cantonal governments.
Zero training on client data
Whisperit does not use your documents, dictations or any other content to train AI models. Your data is used only to process the requests you make.
Compliance and certifications
We comply with the EU GDPR and the Swiss nFADP and act as data processor for your client data, under a standard DPA. Switzerland's EU adequacy decision covers cross-border transfer requirements. SOC 2 Type II is currently in audit with an accredited third-party assessor, and ISO 27001 is on our roadmap.
Whisperit vs US-hosted AI tools
| Feature | Whisperit | US-hosted AI tools |
|---|---|---|
| Data location | Switzerland | USA (typically) |
| GDPR adequacy | ✅ Yes | ⚠️ Requires SCCs |
| nFADP compliant | ✅ Yes | ⚠️ Requires safeguards |
| Vendor reads content | ❌ No | ⚠️ Often yes |
| Used for model training | ❌ No | ⚠️ Often opt-out only |
| Audit logs | ✅ Full | ❌ Limited |
Frequently asked questions
Is it safe to use AI for confidential legal work?
It depends entirely on the tool. Purpose-built legal AI with Swiss or EU hosting, no model training on client data, and zero vendor access can be used safely for confidential work. General-purpose consumer AI tools (ChatGPT, Gemini) are not appropriate for client-confidential legal work.
Where does Whisperit store my data?
Your documents, transcriptions and case data are stored on Swiss infrastructure in ISO 27001-certified data centres, so they are subject to Swiss law rather than US or other foreign jurisdictions. Where the AI processing runs is a separate question, governed by your residency tier: Swiss Only never leaves Switzerland, EU routes through an EU provider, and Global adds an international fallback. The provider-by-provider detail is in the technical data flow document.
Is Whisperit GDPR compliant?
Yes. Whisperit provides a full data processing agreement (DPA). Switzerland has an EU adequacy decision, meaning Swiss-hosted data meets GDPR transfer requirements without additional safeguards.
Can Whisperit access my documents?
No. Whisperit's architecture enforces zero vendor access. Your documents are encrypted and accessible only to members of your workspace.
What encryption standard does Whisperit use?
TLS 1.3 in transit and AES-256 at rest, the same standards used by major financial institutions and government agencies.
What certifications does Whisperit hold?
We comply with the EU GDPR and the Swiss nFADP, and act as data processor for your client data under a standard DPA. SOC 2 Type II is currently in audit with an accredited third-party assessor, and ISO 27001 is on our roadmap. We would rather state where those stand than imply certifications we do not yet hold.
Protect your clients. Use AI you can trust.
Start free. No credit card. Swiss-hosted from day one.