Enterprise Deployment. On your terms.
Hospital groups, health networks, government health organisations and research institutions do not adopt infrastructure that only runs one way. MediVault deploys into Swiss cloud, private cloud, your own data centre, a hybrid split, or a fully air-gapped environment.
- Deployment models
- 5
- P1 response SLA
- 30 min
- Key custody
- BYOK · HYOK
- Pen-test
- Annual, dedicated

Run it on your own
ground, under your own sky.
Swiss cloud, private cloud, on-premise, hybrid or fully air-gapped — the deployment model can put MediVault inside your own estate, on Swiss soil, as literally as a village running on its own utilities. Five models, one jurisdiction either way.
- 5
- Deployment models
- BYOK
- and Hold Your Own Key
- Air-gap
- For classified estates
- Escrow
- Source and key escrow
Rümlang, ZH
Primary production vault
- Role
- Active — read / write primary
- Resilience
- 2N power · N+1 cooling
- Latency
- < 4 ms to Zürich metro
- Attested
- ISO 27001 · ISO 50001 · biometric multi-zone access
Glattbrugg, ZH
Synchronous replica
- Role
- Active — synchronous replication
- Resilience
- 2N power · N+1 cooling
- Latency
- < 2 ms inter-site RTT
- Attested
- ISO 27001 · ISO 22301 business continuity
Meyrin, GE
Disaster recovery vault
- Role
- Warm standby — 15 min RPO
- Resilience
- N+1 power and cooling
- Latency
- < 9 ms Zürich → Genève
- Attested
- ISO 27001 · Swiss data-residency attested
Swiss cloud
Multi-tenant, fully managed, hosted in our Zürich Tier IV facilities.
Private cloud
Single-tenant instance with dedicated compute, storage and key hierarchy.
On-premise
Deployed inside your own data centre, operated by your team or ours.
Hybrid
Keys and sensitive shards on-premise, scale and DR in the Swiss cloud.
Air-gapped
No external network path. Updates delivered by signed, verified media.
What Unternehmen
actually unlocks.
Enterprise is not a bigger version of the standard plan. It changes where the software runs, who holds the keys and what contractual commitments we are prepared to make.
Unlimited records
No per-record ceiling and no overage billing. Enterprise pricing is capacity- and support-based, not a meter that punishes growth.
On-premise deployment
MediVault runs inside your own data centre on your own hardware, operated by your team, our team, or jointly under a defined runbook.
Custom data residency
Contractual residency commitments to a named facility, canton or jurisdiction, with audit rights to verify them.
Air-gapped vault mode
No external network path whatsoever. Updates arrive on signed, verified physical media with a documented chain of custody.
Zero-knowledge architecture
Decryption happens client-side under keys we never hold. MediVault operates the platform without the ability to read its contents.
BYOK and HYOK
Bring Your Own Key supplies the master key from your KMS. Hold Your Own Key keeps it in your HSM, where we can request use but never extraction.
Dedicated support
24/7 named engineers, a 30-minute P1 response SLA, a quarterly service review and a direct escalation path to engineering leadership.
Annual penetration test
A dedicated test of your instance by an independent Swiss firm, scoped with you, with the full unredacted report delivered to your security team.
Source and key escrow
Source code and key material lodged with a Swiss escrow agent, releasable on defined continuity triggers. Standard for public-sector contracts.
The strongest position
has a real cost.
Zero-knowledge means we genuinely cannot read your data. Most vendors describe this as pure upside. It is not — and you should understand the trade before choosing it.
- What we can see
- Ciphertext, record identifiers, sizes, timestamps and access metadata required to operate the service and produce audit evidence.
- What we cannot see
- Clinical content of any kind. In zero-knowledge mode the master key never exists in plaintext inside our infrastructure.
- Key custody
- The master key lives in your HSM or KMS. MediVault requests wrap and unwrap operations; it never receives the key material itself.
- The trade-off
- Server-side search, indexing and the Intelligence layer are unavailable over content we cannot read. Metadata search and full audit remain available.
- Key loss
- If you lose your master key, your data is unrecoverable — by design and without exception. We require a documented key-recovery plan before enabling this mode.
- Verification
- Your security team can independently verify that no plaintext key reaches our infrastructure, using HSM audit logs from your own device.
We will talk you out of it if it is wrong for you. Zero-knowledge suits organisations with mature key-management practice and a hard regulatory driver. For a 40-person clinic, HSM-backed managed keys are the safer operational choice, and we will say so.
Eighteen weeks
from signature to handover.
A hospital-scale deployment is a project, not an install. This is the programme we run, with named owners on both sides and a written gate at each stage.
Discovery & scoping
Architecture review, data inventory, integration map and governance requirements captured as a written scope both sides sign.
Environment build
Instance provisioned in your chosen deployment model, keys generated, policies loaded and identity federation connected.
Migration dry-run
Full rehearsal against a de-identified extract, with reconciliation reporting on every record. Nothing goes live on a first attempt.
Integration & UAT
Connectors certified against your live interfaces, clinical user acceptance testing, and a documented rollback plan for every step.
Cutover
Staged migration with parallel running, out-of-hours cutover windows and on-site engineering presence for hospital-scale moves.
Hypercare & handover
Thirty days of heightened support, followed by handover to your named CSM and a first quarterly service review.
Built for
Swiss public tender.
Public-sector buyers need more than a product. They need documentation that survives a procurement challenge.
- Tender documentation
- Standard responses to WTO/GATT and cantonal procurement requirements, including technical specification, references and financial standing.
- Contracting
- Swiss law, Zürich jurisdiction, with SIK/CSI framework terms accepted. Custom framework agreements negotiated for multi-canton buyers.
- Exit plan
- Documented data-return process, format specification and transition assistance obligations written into the contract from day one.
- Financial standing
- Audited annual accounts, insurance certificates and bank references available to qualified bidders on request.
- Subcontractors
- Full sub-processor register published, with 30 days' advance notice of any change and a customer right to object.
- Escrow
- Source code and key escrow with a Swiss agent, with release conditions agreed in the contract rather than left to goodwill.
Bring your CISO,
your CIO and your lawyer.
Enterprise conversations start with a technical and contractual deep-dive, not a demo. Ninety minutes with our Zürich engineering and legal team, and you leave with written answers.
Tender-ready documentation available under NDA · Swiss law, Zürich jurisdiction