SECURITY & DATA SOVEREIGNTY

Your data is passing through. You stay in control.

Concrete safeguards from the initial request to transfer approval. Here we explain the current implementation and its boundaries.

Data protection starts before the first upload.

Switona processes data for a specific, authorized switch. A provider can initiate a case. That does not grant permission to access or transfer company data.

FrankfurtDatabase, file storage and application region
Separate approvalsData access and the exact transfer
No AI trainingNo migration data sent to external AI models

The path your data takes

01

Request & review

First, define the company, participants, source, destination and scope. Switona independently checks the company, authority and company contact.

02

Digital confirmation

The verified contact receives an email, even without an account. After signing in and verifying a second factor, they sign the digital mandate. Switona reviews it again before enabling data preparation.

03

Preparation & simulation

Authorized files are stored privately. The application analyses structure and types, suggests mappings and reports simulation errors. Only explicitly configured connections are used.

04

Transfer & retention

The exact transfer requires another company approval. Downloading a package is not proof of a destination import. Temporary files are removed after the selected period; evidence has separate retention rules.

Who can access the data?

Access depends on organization, role, case participation and valid company authorization. The API checks these conditions on the server, supplemented by database access policies. A self-declared company name, email address or uploaded document is insufficient.

Internal reviewers cannot appoint themselves or approve their own requests. Sensitive approvals require a fresh second factor. Scope or destination changes can invalidate approvals. Rejection or revocation blocks further operations that require authorization; it cannot retrieve data already transferred into another system.

How are files and credentials protected?

The application uses HTTPS. Both migration files and authority evidence are stored in private buckets. Migration downloads pass through an authenticated server request with a fresh authorization check. Storage encryption at rest follows the respective infrastructure provider’s security measures.

API credentials receive additional AES-256-GCM encryption; the key stays on the server and is not delivered to the browser. REST connections require HTTPS and are checked against internal network destinations. This is not end-to-end encryption: the application must process authorized data to validate and transform it.

Is data sent to AI?

No external AI service is currently connected to migration processing. Suggestions use semantic rules, field names, types and saved mappings. No arbitrary or model-generated code is executed.

Reusable mappings stay within the organization. Raw records are not added to a shared training archive. Any future external model integration must first define its purpose, data scope, provider and processing terms transparently.

What should be agreed before a live transfer?

Data scope, lawful basis, destination access, processing terms, international transfers, retention and evidence periods must fit the actual use. Special-category data and sector-specific obligations need a separate review.

The digital mandate records the declaration, case and timestamps. It is not a qualified electronic signature. The EU Data Act may apply to switching data processing services, but does not give blanket permission to transfer personal data. Switona supports technical delivery and does not replace a legal assessment of the individual case.

Further reading

Updated 29 September 2026. This page describes the technical implementation. See the privacy notice for controller information, data subject rights and website processing.

Your next environment shouldn’t be decided by your old data.

Choose where you go next. We'll help your data get there.