Summary

  • Safe Swiss Cloud AG describes itself as "100% Swiss" and "privately owned", yet the company's own 3 December 2017 announcement confirms that EveryWare AG acquired a majority interest in the firm — corroborated independently by Netzwoche (4 December 2017) and IT Reseller (1 December 2017), with no deal value disclosed.
  • The company states it owns and operates its own data centres, but 2015 trade reporting documents cloud infrastructure hosted at third-party Interxion Glattbrugg colocation alongside an Equinix Switzerland site, and the company's compliance page itself cites the Interxion facility.
  • Capacity, certification and renewal figures — two data centres, more than 10,000 servers, ISO 27001/27017/27018, 100% renewable energy since 2011 — are self-reported and unaudited in the public record.

Every cloud provider sells a story about where its customers' data physically lives and under whose law it falls. Safe Swiss Cloud AG, headquartered at Zurlindenstrasse 52A in Zurich, tells one of the more confident versions: founded in 2013, 100% Swiss owned, operating its own data centres, hosting data exclusively in Switzerland, and — because of that Swiss domicile — "bound only by Swiss, European and accepted International legal practice", a framing the company uses to argue it is not subject to the US CLOUD Act.

The marketing layer is easy to find. The harder question — the one this article asks — is what the verifiable public record says about each layer of that sovereignty claim, and where the layers diverge.

Jurisdiction versus control

It is worth separating two things that sovereign-cloud marketing routinely blurs. Jurisdiction-based sovereignty means the company is incorporated in Switzerland, its data sits in Switzerland, and Swiss and European law govern it. On the company's own statements, all of that is plausibly true and largely self-certifiable.

Control-based sovereignty is a different claim: it asks who owns the equity, who owns the physical assets, and who operates the infrastructure. Here the record is more complicated. Safe Swiss Cloud's own blog post dated 3 December 2017 states plainly that "EveryWare AG has acquired a majority interest in Safe Swiss Cloud AG as part of a cloud cooperation", with both firms continuing as independent brands (company blog, 3 December 2017). The Zurich trade press corroborated the transaction within days: Netzwoche reported on 4 December 2017 that Everyware had acquired a majority share in the Basel-based competitor, noting roughly 90 combined employees and an undisclosed deal value; IT Reseller reported the same on 1 December 2017, naming Everyware CEO Kurt Ris. Wikipedia records the event as a controlling stake acquired in late 2017. PitchBook lists Safe Swiss Cloud as an acquired, operating subsidiary of EveryWare.

None of this makes Safe Swiss Cloud less Swiss — EveryWare is itself a Swiss IT services company. But it does mean that "100% Swiss owned" and "privately owned" on the company's current pages do not, by themselves, tell a buyer whether the majority owner today is a founder, a family, or another operating company, and on what terms. The company's current marketing does not disclose the EveryWare relationship; the most authoritative statements about its ownership are eight years old and predate any disclosed cap-table change.

What does the footprint look like?

The About page states the company owns and operates its own data centres — "2 company data centres" — and that as of October 2019 all platforms are hosted in its own Swiss facilities. The technical FAQ describes two geographically separate data centres in the greater Zurich area, "100% owned by us", alongside a multi-redundant internet backbone.

Yet the historical record shows the footprint has not always been purely self-owned. In May 2015, both IT-Markt and IT Reseller reported that Safe Swiss Cloud was hosting its cloud infrastructure at Interxion's Glattbrugg colocation centre near Zurich, with the Interxion site complementing an earlier footprint at Equinix Switzerland. Interxion is a third-party colocation provider. And the company's own compliance page — the same page asserting "our own world class data centers" — also states: "We use the Interxion data center in Glattbrugg, near Zürich."

The two statements can be reconciled — a company can own dedicated halls inside a rented colocation shell — but the public record does not perform that reconciliation for the buyer. What the record does show is a decade-long pattern of mixed owned and third-party colocation, which is normal industry practice and not a scandal. It is, however, materially different from an unqualified reading of "own data centres".

The self-reported numbers

The company's capacity and compliance figures are stated with precision: more than 1,000 hosts and more than 10,000 servers, customers on four continents, ISO 27001 first obtained in 2015 and ISO 27001/27017/27018 held today, 100% renewable energy since 2011, TÜV certification since 2024 for renewable-energy accounting, and compliance claims spanning GDPR, Swiss data protection, FINMA RS 2018/3, BAIT/BAFIN, HIPAA and FMH.

All of these are self-reported. None is independently audited in any public document this article located. The FINMA reference on the compliance page cites a KPMG document that was not retrieved; the certification claims are asserted, not evidenced by certificate numbers or audit dates. That does not make them false — Swiss providers of this profile commonly hold the certifications they list. It makes them unverified, which is a different thing, and matters precisely for a vendor whose pitch is that customers should trust claims over geography.

The same applies to the AI story. The homepage advertises private AI stacks with GPU pools in Switzerland and the EU — a timely offer given European demand for non-US compute — but the public record contains no disclosed GPU counts, no named AI customers and no performance or utilisation data. The AI-capacity claim is, at present, a positioning statement.

Founding year: a small discrepancy with a lesson

A minor detail illustrates the evidence discipline the topic requires. The company and Wikipedia say Safe Swiss Cloud was founded in 2013. PitchBook's profile lists 2009. One of the two is wrong, or the 2009 date reflects an earlier legal entity. The public record does not resolve it. Small, but a reminder that even basic facts about a private Swiss company require triangulation — and that some will not triangulate.

What a buyer should actually verify

For an enterprise evaluating Safe Swiss Cloud, the gaps the record leaves open translate into specific questions: the current ownership structure and any shareholder agreement with EveryWare AG; which halls are owned outright versus leased within Interxion or Equinix shells; certificate numbers and audit scopes for each ISO claim; the contractual basis for the CLOUD Act non-subjection argument, which is a legal position, not a treaty fact; and the concrete scale and operational maturity of the GPU offering.

The pattern across all five is the same: Safe Swiss Cloud's positioning is not empty marketing — the Swiss incorporation, Swiss data residency and Swiss law governing are well-supported — but the strongest claims about control, capacity and certification sit in a gap between self-description and independent evidence. Sovereignty, in the end, is a claim about control, and control is the one thing the public record can only partially confirm.