Resources

Guide · Residency

AI agent data residency: what “Swiss” actually means

What Swiss data residency really means for AI agents — FADP basics, the storage-versus-processing distinction vendors blur, CLOUD Act exposure, and the questions to ask any provider.

Data residency for an AI agent is the question of where the agent’s state — your conversations, memory, documents, credentials — physically lives, and under whose law. It sounds simple and is routinely blurred: “Swiss hosting,” “EU-based,” and “sovereign cloud” get used as vibes rather than claims, and an agent’s data takes more paths than most vendors map.

This guide gives you the vocabulary to pin vendors down: what Switzerland’s FADP requires, why storage and processing are different questions with different answers, where the US CLOUD Act reaches, and what to ask any provider — including us. An agent is a harder residency problem than a database, because it does not just hold your data; it continuously sends slices of it to model inference, which may run somewhere else entirely. Precision here is the whole game. Nothing below is legal advice.

What does the Swiss FADP require?

The Federal Act on Data Protection (FADP) is Switzerland’s data-protection law; its fully revised version (revFADP) has been in force since September 2023 and tracks the GDPR closely — privacy by design and by default, processing records, breach notification, and strong rules on moving personal data abroad. Data may flow freely only to countries the Federal Council recognises as adequate; elsewhere needs safeguards like standard contractual clauses.

Two points matter for choosing an agent. First, the FADP applies to the processing of personal data concerning Swiss persons broadly — a Swiss fiduciary or practice using an AI agent is doing regulated processing, wherever the vendor sits, and remains responsible for the processors it engages. Second, “stored in Switzerland” is not itself an FADP requirement — the law governs how data is protected and transferred, not a flag on a datacenter. Residency in Switzerland is better understood as a posture: it keeps data under a strong, GDPR-adequate legal regime, simplifies the cross-border analysis, and is what many Swiss professional clients simply expect of their advisers.

Storage versus processing: the distinction vendors blur

Storage is where data persists at rest — the databases and buckets holding your conversations, memory, and documents. Processing is everywhere data exists in motion or in use: the runtime executing the agent, the edge handling requests, and above all the GPUs running model inference. These routinely sit in different countries, which is why a vague “hosted in Switzerland” can be technically true and materially misleading.

For an AI agent the inference path is the one to interrogate, because it is continuous and invisible: every turn sends context — which can include anything the agent knows about you — to wherever the model runs. A vendor can store your data in Zurich and send every prompt to US-operated inference; residency of the database tells you nothing about that. The honest way to describe a real architecture is to name each path separately. monopea’s own phrasing is deliberately split — stored in Switzerland, processed in the EU — precisely because a single word cannot carry both claims. When a vendor uses one word, ask which path it describes; when they say “sovereign,” ask what, concretely, is sovereign about it.

  • Storage: where state persists at rest — the easiest claim to make and verify
  • Processing: runtime, edge, and inference — where your data actually travels each turn
  • Inference: the path most often elsewhere, and least often disclosed

Where does the US CLOUD Act reach?

The CLOUD Act (2018) lets US authorities compel providers subject to US jurisdiction to produce data in their possession or control regardless of where it is stored. A US hyperscaler’s Swiss region is therefore Swiss geography under US legal reach: location and jurisdiction are different axes, and a datacenter address does not settle the second one.

Be equally honest about the limits of the concern: CLOUD Act orders are targeted legal process, disclosure obligations can conflict with Swiss law (a genuine tension, contested case by case), and encryption changes what possession is worth — a provider compelled to hand over envelope-encrypted blobs without keys hands over much less. The clean way to think about any vendor, including us: (1) where is data stored, (2) where is it processed — inference included, (3) which entities in the chain answer to which jurisdictions, and (4) what does encryption make an order actually yield? Vendors who answer all four plainly are telling you something; vendors who answer with “sovereign” are telling you something too.

What should you ask any vendor?

Six questions separate a residency architecture from a residency slogan. Where is my persistent data stored, and can you name the city? Where does processing run — runtime, edge, and model inference, each separately? Can I choose models whose inference stays in a jurisdiction I pick? Which providers sit in the chain, and under which law? How are credentials stored, and can any component read them back? Can I inspect and delete what the agent retains about me?

The pattern to reward is specificity. “Zurich” beats “Switzerland” beats “Europe” beats “sovereign.” A vendor who volunteers the storage/processing split, names their sub-processors, and tells you plainly which claims they cannot make is showing you how they will behave about everything else. A vendor whose answer to every question is the same word is selling the word.

  • Name the city for storage; name each path for processing — inference included
  • Ask which entities answer to which jurisdictions, not just where servers sit
  • Ask what an order would actually yield, given the encryption design

What is the Swiss AI ecosystem worth to you?

Residency for agents got materially easier when serious inference became available inside Switzerland. Infomaniak, the Geneva-based hosting company, serves open-weight models from Swiss datacenters — which means the hardest residency path, inference, can now genuinely stay in-country rather than defaulting to US or pan-EU endpoints. For Swiss practices, that closes the loop that “Swiss storage” alone never could.

The ecosystem is deepening beneath that: Apertus, the fully open, multilingual model built by ETH Zurich and EPFL on Swiss public infrastructure, is a statement that transparent, domestically trained models are viable — worth knowing as context for where Swiss-resident AI is heading. (Ecosystem context, to be clear: Apertus is not part of monopea’s model roster.) The practical takeaway: “inference in Switzerland” is no longer an unreasonable ask, so a vendor who cannot offer any Swiss-resident inference path is making a choice, not facing a constraint.

How Monopea handles residency

Stored in Switzerland. Processed in the EU. Concretely: your persistent data — conversations, memory, knowledge graph, documents, encrypted secrets — is stored in Zurich, Switzerland; the agent runtime and edge run on EU infrastructure. We phrase it as a pair on purpose: we will not claim “your data never leaves Switzerland,” because for our architecture that would be false, and vendors who say it about similar architectures are blurring exactly the distinction this guide teaches.

On the inference path — the hard one — monopea’s Swiss track runs Infomaniak-hosted open-weight models (Qwen3.5-397B, Mistral 24B, Nemotron), so inference stays in Switzerland when you choose it; other models in the roster (Claude, GPT, Gemini, and others) run on their providers’ infrastructure, and choosing them is your call, made with the path visible. Credentials sit in a write-only, envelope-encrypted vault that even you cannot read back; memory is inspectable and revocable. Judge us with the six questions above — that is what they are for.

What to take away

Split every claim in two

Storage and processing are different questions with different answers. Any vendor sentence containing one location word for both — “Swiss hosting,” “sovereign cloud” — is hiding at least one path, usually inference.

Jurisdiction is not geography

A US provider’s Swiss region is Swiss soil under US legal reach. Ask which entities in the chain answer to which law, and what an order would actually yield given the encryption design.

Inference can now stay in-country

With Infomaniak serving open-weight models from Swiss datacenters — and Apertus signaling where the ecosystem is heading — Swiss-resident inference is a real option. A vendor offering none is choosing not to.

FAQ

Swiss data residency, in short

What does data residency mean for an AI agent?
Where the agent’s state lives at rest (storage), and where it travels in use (processing) — runtime, edge, and especially model inference, which sends slices of your context somewhere every turn. The two are different questions; honest vendors answer them separately, with place names.
Does the FADP require my data to stay in Switzerland?
No — the revised FADP governs how personal data is protected and transferred, permitting flows to adequate countries and requiring safeguards elsewhere. Swiss residency is a posture that simplifies that analysis and meets client expectations, not a literal legal mandate for most businesses. Not legal advice.
Is data stored in a US provider’s Swiss region safe from the CLOUD Act?
Storage location does not remove it from reach: the CLOUD Act lets US authorities compel providers under US jurisdiction to produce data they control, wherever stored. What matters is which entities control the data and keys, and what an order would actually yield given the encryption design.
Where does Monopea store and process my data?
Persistent data is stored in Zurich, Switzerland; processing runs on EU infrastructure. On the Swiss model track, inference runs on Infomaniak-hosted open-weight models in Switzerland; choose Claude, GPT, or Gemini and inference runs with those providers — the path is visible either way.