# LLMOps Sovereignty: Your AI Data Deserves Swiss Law

AI and LLM operations are the newest sovereignty frontier. Every prompt you send, every fine-tuning dataset you upload, every model output you receive contains business intelligence. When you use OpenAI's API, Azure OpenAI, AWS Bedrock, or Google Vertex AI, that data flows through US infrastructure, governed by US law, and accessible under the [CLOUD Act](https://en.wikipedia.org/wiki/CLOUD_Act) without Swiss judicial process.

Running LLM infrastructure on Swiss soil under Swiss law is the only way to keep your AI interactions outside foreign jurisdiction. VSHN has been the DevOps company since 2014, now bringing that operational experience to LLM workloads. But sovereignty is more than where GPUs are located. The EU Cloud Sovereignty Framework defines eight dimensions that determine whether your provider is truly sovereign.

## Why open-source LLM tooling strengthens sovereignty

Proprietary AI platforms lock you into a single vendor's API, pricing, and terms of service. Open-source LLM infrastructure ([vLLM](https://www.vllm.ch/), [LiteLLM](https://www.litellm.ch/), [llm-d](https://www.llm-d.ch/)) gives you:

- **No vendor lock-in**: switch models, providers, or hosting at any time
- **Full auditability**: inspect every component in your inference pipeline
- **Data stays in Switzerland**: prompts and outputs remain on Swiss infrastructure under Swiss law
- **Community-governed**: no single company controls your AI stack's roadmap

VSHN deploys and operates LLM infrastructure on Swiss Kubernetes clusters using [vLLM](https://www.vllm.ch/) for high-throughput inference, [LiteLLM](https://www.litellm.ch/) for multi-provider gateways, and [llm-d](https://www.llm-d.ch/) for distributed serving. Combined with Swiss ownership and operations, this creates a fully sovereign AI stack.

## LLMOps sovereignty compared

| Dimension | OpenAI API | Azure OpenAI | AWS Bedrock | Google Vertex AI | VSHN LLMOps |
|-----------|-----------|-------------|------------|-----------------|-------------------|
| **Ownership** | OpenAI (USA) | Microsoft (USA) | Amazon (USA) | Google (USA) | VSHN AG (Switzerland) |
| **Governing law** | US law | US law | US law | US law | Swiss law |
| **CLOUD Act** | Exposed | Exposed | Exposed | Exposed | Not exposed |
| **Data location** | USA | Regional (US-controlled) | Regional (US-controlled) | Regional (US-controlled) | Switzerland (Cloudscale, Exoscale, or your choice) |
| **Software stack** | Proprietary | Proprietary | Proprietary | Proprietary | Open source ([vLLM](https://www.vllm.ch/), [LiteLLM](https://www.litellm.ch/), [llm-d](https://www.llm-d.ch/), Kubernetes) |
| **Prompt data access** | Provider has access, may use for training | Microsoft has access | Amazon has access | Google has access | VSHN has operational access only for authorized support — never used for model training |
| **Operations team** | USA | USA | USA | USA | Switzerland ([Swiss-only option](https://products.vshn.ch/support_plans.html#_option_switzerland_only_support)) |
| **Certifications** | SOC 2 | SOC 2, ISO 27001 | SOC 2, ISO 27001 | SOC 2, ISO 27001 | [ISO 27001](https://www.vshn.ch/wp-content/uploads/2025/12/ISO-27001-certificate-VSHN-2024.pdf), ISAE 3402 Type II |

## VSHN sovereignty self-assessment

We applied the EU's [Cloud Sovereignty Framework](https://commission.europa.eu/document/09579818-64a6-4dd5-9577-446ab6219113_en) (v1.2.1, October 2025) to our own services. This framework was used to score providers in the EU's [EUR 180M sovereign cloud tender](https://ec.europa.eu/commission/presscorner/detail/en/ip_26_833) in April 2026. Three pure-European providers achieved SEAL-3, while a consortium involving Google Cloud scored only SEAL-2.

*This is a self-assessment, not a formal SEAL certification. We publish it for transparency so customers can evaluate our sovereignty profile using the same structured criteria the EU uses.*

| # | Dimension | Weight | Assessment | Evidence |
|---|-----------|--------|-----------|----------|
| SOV-1 | Strategic | 15% | **Strong** | Swiss AG, no foreign parent, all shareholders Swiss citizens ([Commercial Register](https://zh.chregister.ch/cr-portal/auszug/auszug.xhtml?uid=CHE-275.566.226)) |
| SOV-2 | Legal | 10% | **Strong** | Swiss law ([GTC](https://products.vshn.ch/legal/gtc_en.html)), no CLOUD Act, [EU adequacy decision](https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en) |
| SOV-3 | Data & AI | 10% | **Strong** | Swiss DCs by default. Sovereign key management via [Managed OpenBao](https://www.openbao.ch) + [Swiss HSM](https://cloud.securosys.com/cloudhsm) |
| SOV-4 | Operational | 15% | **Strong** | Swiss 24/7 ops, [Swiss-only support option](https://products.vshn.ch/support_plans.html#_option_switzerland_only_support). All services on vanilla Kubernetes |
| SOV-5 | Supply Chain | 20% | **Strong** | Infrastructure-agnostic — [customer chooses provider](https://servala.com/providers/). Open-source software |
| SOV-6 | Technology | 15% | **Strong** | 100% open source. VSHN contributes to [K8up](https://github.com/k8up-io) (CNCF), [Crossplane providers](https://github.com/vshn), [Project Syn](https://github.com/projectsyn) |
| SOV-7 | Security | 10% | **Strong** | [ISO 27001](https://www.vshn.ch/wp-content/uploads/2025/12/ISO-27001-certificate-VSHN-2024.pdf), ISAE 3402 Type II, Swiss SOC. [FINMA-regulated customers](https://www.vshn.ch/en/solutions/solutions-for-banks-and-financial-service-providers/) |
| SOV-8 | Environmental | 5% | **Moderate** | DC operators: Green Datacenter AG (ISO 22301/27001/27701), [Exoscale sustainability](https://www.exoscale.com/sustainability/). [VSHN CSR policy](https://handbook.vshn.ch/corporate_social_responsibility_policy.html) |

**Overall: SEAL-3 equivalent**, the same level achieved by the winners of the EU's own sovereignty tender. No provider worldwide achieved SEAL-4: it requires fully EU/EEA-sourced hardware supply chains and open-source foundations, structural gaps shared by every cloud provider.

Try Swiss infrastructure: [APPUiO](https://www.appuio.ch) (managed Kubernetes, free trial), [Exoscale]({{partner:exoscale.signup_url}}) (Swiss IaaS). Want help choosing? [Contact us](#contact).

## Get a sovereignty assessment for your LLM infrastructure

If you're using US-hosted AI APIs or evaluating sovereign alternatives, [contact us](#contact) for a free consultation. We assess your current setup against the EU framework and design an LLM infrastructure that keeps your prompts, training data, and model outputs under Swiss jurisdiction.
