Security is not an option, it is the architecture
Walterdesk was designed from the ground up for sensitive business data: complete isolation per customer, systematic encryption, and verifiable Swiss FADP compliance.

Encryption at rest
All stored data - conversations, files, metadata - are encrypted with AES-256-GCM, the standard recommended algorithm for sensitive data. Keys are managed separately from data and undergo regular rotation.
Encryption in transit
All exchanges between your collaborators and your instance, as well as between our internal services, are protected by TLS 1.3. Obsolete protocols are disabled and certificates are renewed automatically.
Tenant isolation
Each organisation has its own application container and database. No application resources are shared between customers: a hypothetical vulnerability in one tenant never exposes another's data.
Role-based access control (RBAC)
Owner, administrator, member: each role has strictly defined permissions. Billing, instance configuration, and user management are reserved for administrators. The principle of least privilege also applies to our internal teams.
Audit logs
Sensitive actions - logins, invitations, role changes, configuration modifications - are logged with timestamps. On the Enterprise plan, these logs can be viewed and exported, with configurable retention up to 3 years.
Encrypted backups
Your instance is backed up automatically (every 24h on Starter, 6h on Business, 1h on Enterprise). Backups are encrypted before storage and kept in Switzerland, on a site separate from production.
Secret management
API keys for model providers, database credentials, and certificates are stored in a dedicated secret manager, never in the code or container images. Each secret is tracked and individually revocable.
Continuous testing and hardening
Automated dependency analysis, systematic code reviews, and regular security tests on the infrastructure. The Enterprise plan includes reinforced hardening of the dedicated instance (restricted network, additional policies).
Compliance and rights over your data
Compliance is not declared, it is demonstrated. Here are our contractual commitments, valid on all plans.
Swiss FADP and GDPR compliance
Exclusive hosting in Switzerland, documented processing register, contractually identified subprocessors. Your conversations are never used to train models, neither ours nor those of third parties.
Right to export
You can export all of your organisation's data - conversations, files, user lists - in standard formats, at any time and without fees. Your data belongs to you, including the day you leave.
Right to deletion
Upon termination, your data is deleted from production immediately and from backups at the end of their retention cycle. A complete early deletion can be requested and is subject to written confirmation.
And what about AI model providers?
When your employees query a model, the request transits through your Swiss instance, which calls the provider's API under professional contracts excluding data usage for training. Storage - conversations, histories, files - remains entirely in Switzerland. You also choose which models are enabled: it is possible to restrict your instance to European models only.