shield_lockSecurity & Trust

Security that
Swiss companies
trust.

TLS-encrypted transfer. Core platform and stored data in the Supabase project region in Zurich; external services as described in the privacy policy. Our measures are aligned with revFADP requirements; external and legal review is still pending.

Four pillars

Trust isn't a feature.
It's the foundation.

lock

Encrypted transfer and storage

Data is encrypted in transit with TLS and encrypted at rest within the platform.

location_on

Platform data in Zurich

Core platform and stored data are located in the Supabase project region in Zurich. External services, including website delivery, email dispatch and identity verification, are listed in the privacy policy.

gavel

Aligned with revFADP requirements

The technical and organisational measures are aligned with revFADP requirements; external and legal review is still pending.

verified_user

Controlled data access

Access to protected platform data is authenticated and authorised; Row Level Security and role-based permissions restrict it. Public and integration endpoints are secured separately with controls appropriate to each endpoint.

Data flow

This is how your data moves.
And this is how it doesn't.

person
Step 01

User

A change is entered — once.

lock
Step 02

Encryption

TLS-encrypted transfer and encrypted storage within the platform.

dns
Step 03

Supabase Zurich region

Core platform and stored data are located in the Supabase project region in Zurich.

fact_check
Step 04

Verification

Multi-stage check: identity, authorisation, consistency — before any data is passed on.

business
Step 05

Company

Only approved partners with explicit user consent receive the change.

boltReal-time transmission · Security-relevant approvals and delivery events are logged.
Standards & compliance

The standards we hold ourselves to.

We communicate what is live transparently — never prematurely. Further certifications are on our roadmap.

revDSGExternal review pending

Aligned with Swiss data protection law requirements; legal approval is pending.

GDPRExternal review pending

GDPR requirements for applicable EU cases are considered; legal approval is pending.

What we don't do

Some promises
are worth more in their absence.

block

We don't sell data

Not to ad networks. Not to data brokers. Not to “partners”. Never. Connect PD is funded through contracts with business customers, not by monetising your identity.

block

No advertising trackers

No Meta Pixel, no session recording, no retargeting pixels. Audience measurement (Google Analytics) runs only with your consent — anonymised and revocable at any time.

block

No cross-site tracking

No advertising cookies, no fingerprinting scripts, no retargeting pixels. Our website works entirely without them.

block

Location of platform data

Core platform and stored data are located in the Supabase project region in Zurich. External services, possible international transfers and contractual safeguards are listed in the privacy policy.

See it
for yourself.

Request our Security Brief — with technical architecture, threat model and current compliance status.