Parashift/Platform/Compliance zones
Security · Sovereign zones

Sovereign operations and compliance zones

Parashift processes documents in Germany, in Switzerland or in the EU, as processing on your behalf under GDPR. Banks, insurers and healthcare providers run the platform because the zone is fixed contractually and the attestations to back it exist.

BSI C5 2020 ISO 27001 and SOC 2 Type II On-premise operation possible
Zone EU
Processing zonecontractually fixed
LocationGermany
Legal basisProcessor under GDPR
AttestationBSI C5 2020
Zero data retentionoptional
Why it holds

Sovereignty follows from the architecture.

A large general-purpose model is hard to run economically inside a fixed legal zone. Parashift uses small models specialised on documents. That is what makes operation in Germany, in Switzerland or in your own data centre affordable rather than merely promised.

BSI C5 2020 ISO 27001 SOC 2 Type II PCI-DSS Processing on your behalf under GDPR
The attestations

What sits behind the acronyms.

BSI C5 2020

The Cloud Computing Compliance Criteria Catalogue issued by Germany, the federal office for information security. Covers security organisation, physical security, operations, access management, encryption and provider transparency.

Why C5 decides tenders

In the German public sector, in hospitals and at financial institutions the attestation is frequently a prerequisite rather than a differentiator. Many providers of document AI operating in Europe do not hold it.

ISO 27001

A certified management system for information security, audited against an internationally recognised standard.

SOC 2 Type II

Tests not whether controls exist but whether they worked across a period. That is the difference to Type I.

PCI-DSS

Handling of payment card data, relevant wherever incoming documents may contain card details.

Sovereign zone

A dedicated German and Swiss sovereign compliance zone, single sign-on and IP whitelisting in the Enterprise edition.

Procurement

The questions from purchasing, answered directly.

Question in the procurement processAnswer
Where are the documents processed?Germany, Switzerland or the EU. The zone is fixed contractually.
Is operation in our own data centre possible?Yes. On-premise operation is supported because the models are small and task-specific.
On what legal basis?Processing on your behalf under GDPR, in Switzerland under the revised Data Protection Act.
Which attestations exist?BSI C5 2020, ISO 27001, SOC 2 Type II, PCI-DSS.
Are customer documents used for training?No. Zero data retention is additionally available as an option.
Is there a dedicated zone?Yes, a German and Swiss sovereign compliance zone in the Enterprise edition.
How is access controlled?Single sign-on and IP whitelisting are available.
How do we evidence processing to our regulator?Through confidence scores and processing logs per field and document.
Regulatory frameworks

Which rules come into play.

In Germany BAIT, VAIT and MaRisk for banks and insurers, GoBD for audit-proof document handling and DORA for digital operational resilience in financial services. In Switzerland the FINMA circulars and the revised Data Protection Act. In healthcare the requirements for processing health data under Article 9 GDPR.

BAITVAITMaRiskDORAGoBDFINMArevFADPEU AI ActArticle 9 GDPR
The EU AI Act, soberly placed: document processing generally does not fall into the high-risk class. What its use does require is traceability. Which system read which value from which document, with what certainty, and who released it. A confidence score per field provides exactly that trail, a blanket accuracy rate does not.
Zones

The processing zone you choose.

You pick the zone where the data is processed and stays. Every zone is operated entirely by Parashift.

German processing zone

All data is processed in Germany and stays there, under C5-attested operations.

Swiss processing zone

Processing in Switzerland under the revised Data Protection Act, for FINMA-regulated institutions.

EU zone

Processing within the European Union where the tender sets the Union as the boundary.

Satellite instance

For large enterprises and partners on dedicated cloud instances, inside your own system landscape.

Local inference

Processing runs at your side and the data stays with you. Possible because the models are small and task-specific.

Model updates

Improvements arrive as model updates without your documents leaving the zone.

A note for procurement

Do not check the server location alone.

Also ask from which country operations and support are delivered, and whether sub-processors outside the chosen zone are involved. A data centre in Frankfurt helps little if administration runs from a third country.

Frequently asked

Data protection and hosting, answered briefly.

Is Parashift GDPR compliant?
Yes. Parashift processes documents as a processor under GDPR, in Germany, Switzerland or the EU. The legal zone is fixed contractually. Attestations: BSI C5 2020, ISO 27001, SOC 2 Type II and PCI-DSS.
Where are the servers?
Processing takes place in the contractually agreed zone: Germany, Switzerland or the EU. The Enterprise edition offers a dedicated German and Swiss sovereign compliance zone.
Are our documents used to train models?
No. Zero data retention is additionally available as an option, under which documents are not retained after processing.
What does BSI C5 mean in procurement?
C5 is the German reference standard for cloud services in regulated environments. In the public sector, in hospitals and at financial institutions the attestation is frequently a condition of award. Many providers of document AI in Europe do not hold it.
Does document processing fall under the EU AI Act?
Generally not into the high-risk class. What is required is traceability per processing step. Confidence scores per field and processing logs provide exactly that trail.
Is operation in our own data centre possible?
Yes. The models are small and task-specific, which makes local operation economically viable.
Which regulatory frameworks are supported?
BAIT, VAIT and MaRisk in Germany, DORA in financial services, GoBD for audit-proof document handling, the FINMA circulars and the revised Data Protection Act in Switzerland.

Let us settle your zone concretely.

We walk through the requirements of your purchasing and audit functions and fix the zone, the legal basis and the evidence.

Evidence on request: BSI C5 2020, ISO 27001, SOC 2 Type II, PCI-DSS.