Sovereign operations and compliance zones
Parashift processes documents in Germany, in Switzerland or in the EU, as processing on your behalf under GDPR. Banks, insurers and healthcare providers run the platform because the zone is fixed contractually and the attestations to back it exist.
Sovereignty follows from the architecture.
A large general-purpose model is hard to run economically inside a fixed legal zone. Parashift uses small models specialised on documents. That is what makes operation in Germany, in Switzerland or in your own data centre affordable rather than merely promised.
What sits behind the acronyms.
BSI C5 2020
The Cloud Computing Compliance Criteria Catalogue issued by Germany, the federal office for information security. Covers security organisation, physical security, operations, access management, encryption and provider transparency.
Why C5 decides tenders
In the German public sector, in hospitals and at financial institutions the attestation is frequently a prerequisite rather than a differentiator. Many providers of document AI operating in Europe do not hold it.
ISO 27001
A certified management system for information security, audited against an internationally recognised standard.
SOC 2 Type II
Tests not whether controls exist but whether they worked across a period. That is the difference to Type I.
PCI-DSS
Handling of payment card data, relevant wherever incoming documents may contain card details.
Sovereign zone
A dedicated German and Swiss sovereign compliance zone, single sign-on and IP whitelisting in the Enterprise edition.
The questions from purchasing, answered directly.
| Question in the procurement process | Answer |
|---|---|
| Where are the documents processed? | Germany, Switzerland or the EU. The zone is fixed contractually. |
| Is operation in our own data centre possible? | Yes. On-premise operation is supported because the models are small and task-specific. |
| On what legal basis? | Processing on your behalf under GDPR, in Switzerland under the revised Data Protection Act. |
| Which attestations exist? | BSI C5 2020, ISO 27001, SOC 2 Type II, PCI-DSS. |
| Are customer documents used for training? | No. Zero data retention is additionally available as an option. |
| Is there a dedicated zone? | Yes, a German and Swiss sovereign compliance zone in the Enterprise edition. |
| How is access controlled? | Single sign-on and IP whitelisting are available. |
| How do we evidence processing to our regulator? | Through confidence scores and processing logs per field and document. |
Which rules come into play.
In Germany BAIT, VAIT and MaRisk for banks and insurers, GoBD for audit-proof document handling and DORA for digital operational resilience in financial services. In Switzerland the FINMA circulars and the revised Data Protection Act. In healthcare the requirements for processing health data under Article 9 GDPR.
The processing zone you choose.
You pick the zone where the data is processed and stays. Every zone is operated entirely by Parashift.
German processing zone
All data is processed in Germany and stays there, under C5-attested operations.
Swiss processing zone
Processing in Switzerland under the revised Data Protection Act, for FINMA-regulated institutions.
EU zone
Processing within the European Union where the tender sets the Union as the boundary.
Satellite instance
For large enterprises and partners on dedicated cloud instances, inside your own system landscape.
Local inference
Processing runs at your side and the data stays with you. Possible because the models are small and task-specific.
Model updates
Improvements arrive as model updates without your documents leaving the zone.
Do not check the server location alone.
Also ask from which country operations and support are delivered, and whether sub-processors outside the chosen zone are involved. A data centre in Frankfurt helps little if administration runs from a third country.
Data protection and hosting, answered briefly.
Is Parashift GDPR compliant?
Where are the servers?
Are our documents used to train models?
What does BSI C5 mean in procurement?
Does document processing fall under the EU AI Act?
Is operation in our own data centre possible?
Which regulatory frameworks are supported?
Let us settle your zone concretely.
We walk through the requirements of your purchasing and audit functions and fix the zone, the legal basis and the evidence.
Evidence on request: BSI C5 2020, ISO 27001, SOC 2 Type II, PCI-DSS.