Skip to content
Product 06 · Your infrastructure, your rules

Enterprise Deployment. On your terms.

Hospital groups, health networks, government health organisations and research institutions do not adopt infrastructure that only runs one way. MediVault deploys into Swiss cloud, private cloud, your own data centre, a hybrid split, or a fully air-gapped environment.

Deployment models
5
P1 response SLA
30 min
Key custody
BYOK · HYOK
Pen-test
Annual, dedicated
Chalets scattered across a green Swiss mountainside beneath open sky.
Sovereignty, not a sales term

Run it on your own
ground, under your own sky.

Swiss cloud, private cloud, on-premise, hybrid or fully air-gapped — the deployment model can put MediVault inside your own estate, on Swiss soil, as literally as a village running on its own utilities. Five models, one jurisdiction either way.

5
Deployment models
BYOK
and Hold Your Own Key
Air-gap
For classified estates
Escrow
Source and key escrow
Request an enterprise briefing
ZH-DC-01Tier IV

Rümlang, ZH

Primary production vault

Role
Active — read / write primary
Resilience
2N power · N+1 cooling
Latency
< 4 ms to Zürich metro
Attested
ISO 27001 · ISO 50001 · biometric multi-zone access
ZH-DC-02Tier IV

Glattbrugg, ZH

Synchronous replica

Role
Active — synchronous replication
Resilience
2N power · N+1 cooling
Latency
< 2 ms inter-site RTT
Attested
ISO 27001 · ISO 22301 business continuity
GE-DC-03Tier III+

Meyrin, GE

Disaster recovery vault

Role
Warm standby — 15 min RPO
Resilience
N+1 power and cooling
Latency
< 9 ms Zürich → Genève
Attested
ISO 27001 · Swiss data-residency attested

Swiss cloud

Multi-tenant, fully managed, hosted in our Zürich Tier IV facilities.

Best fit
Clinics and hospitals wanting zero infrastructure burden

Private cloud

Single-tenant instance with dedicated compute, storage and key hierarchy.

Best fit
Groups with isolation requirements from their CISO

On-premise

Deployed inside your own data centre, operated by your team or ours.

Best fit
Institutions with existing estate and sovereignty policy

Hybrid

Keys and sensitive shards on-premise, scale and DR in the Swiss cloud.

Best fit
Networks balancing control against operational cost

Air-gapped

No external network path. Updates delivered by signed, verified media.

Best fit
Classified, forensic and public-sector environments
127
Healthcare sites live
Clinics, hospitals and networks
38 ms
Median API response
FHIR R4 read, p50, Swiss edge
1.2 bn
Audit events written
Cryptographically signed, immutable
18
EHR systems connected
Certified production connectors
6
Independent audits / year
Pen-test, SOC 2, ISO surveillance
30 min
P1 incident response
24/7 Swiss-based on-call

What Unternehmen
actually unlocks.

Enterprise is not a bigger version of the standard plan. It changes where the software runs, who holds the keys and what contractual commitments we are prepared to make.

Unlimited records

No per-record ceiling and no overage billing. Enterprise pricing is capacity- and support-based, not a meter that punishes growth.

On-premise deployment

MediVault runs inside your own data centre on your own hardware, operated by your team, our team, or jointly under a defined runbook.

Custom data residency

Contractual residency commitments to a named facility, canton or jurisdiction, with audit rights to verify them.

Air-gapped vault mode

No external network path whatsoever. Updates arrive on signed, verified physical media with a documented chain of custody.

Zero-knowledge architecture

Decryption happens client-side under keys we never hold. MediVault operates the platform without the ability to read its contents.

BYOK and HYOK

Bring Your Own Key supplies the master key from your KMS. Hold Your Own Key keeps it in your HSM, where we can request use but never extraction.

Dedicated support

24/7 named engineers, a 30-minute P1 response SLA, a quarterly service review and a direct escalation path to engineering leadership.

Annual penetration test

A dedicated test of your instance by an independent Swiss firm, scoped with you, with the full unredacted report delivered to your security team.

Source and key escrow

Source code and key material lodged with a Swiss escrow agent, releasable on defined continuity triggers. Standard for public-sector contracts.

The strongest position
has a real cost.

Zero-knowledge means we genuinely cannot read your data. Most vendors describe this as pure upside. It is not — and you should understand the trade before choosing it.

What we can see
Ciphertext, record identifiers, sizes, timestamps and access metadata required to operate the service and produce audit evidence.
What we cannot see
Clinical content of any kind. In zero-knowledge mode the master key never exists in plaintext inside our infrastructure.
Key custody
The master key lives in your HSM or KMS. MediVault requests wrap and unwrap operations; it never receives the key material itself.
The trade-off
Server-side search, indexing and the Intelligence layer are unavailable over content we cannot read. Metadata search and full audit remain available.
Key loss
If you lose your master key, your data is unrecoverable — by design and without exception. We require a documented key-recovery plan before enabling this mode.
Verification
Your security team can independently verify that no plaintext key reaches our infrastructure, using HSM audit logs from your own device.

We will talk you out of it if it is wrong for you. Zero-knowledge suits organisations with mature key-management practice and a hard regulatory driver. For a 40-person clinic, HSM-backed managed keys are the safer operational choice, and we will say so.

Eighteen weeks
from signature to handover.

A hospital-scale deployment is a project, not an install. This is the programme we run, with named owners on both sides and a written gate at each stage.

Discovery & scoping

Architecture review, data inventory, integration map and governance requirements captured as a written scope both sides sign.

Environment build

Instance provisioned in your chosen deployment model, keys generated, policies loaded and identity federation connected.

Migration dry-run

Full rehearsal against a de-identified extract, with reconciliation reporting on every record. Nothing goes live on a first attempt.

Integration & UAT

Connectors certified against your live interfaces, clinical user acceptance testing, and a documented rollback plan for every step.

Cutover

Staged migration with parallel running, out-of-hours cutover windows and on-site engineering presence for hospital-scale moves.

Hypercare & handover

Thirty days of heightened support, followed by handover to your named CSM and a first quarterly service review.

Built for
Swiss public tender.

Public-sector buyers need more than a product. They need documentation that survives a procurement challenge.

Tender documentation
Standard responses to WTO/GATT and cantonal procurement requirements, including technical specification, references and financial standing.
Contracting
Swiss law, Zürich jurisdiction, with SIK/CSI framework terms accepted. Custom framework agreements negotiated for multi-canton buyers.
Exit plan
Documented data-return process, format specification and transition assistance obligations written into the contract from day one.
Financial standing
Audited annual accounts, insurance certificates and bank references available to qualified bidders on request.
Subcontractors
Full sub-processor register published, with 30 days' advance notice of any change and a customer right to object.
Escrow
Source code and key escrow with a Swiss agent, with release conditions agreed in the contract rather than left to goodwill.
Enterprise Deployment

Bring your CISO,
your CIO and your lawyer.

Enterprise conversations start with a technical and contractual deep-dive, not a demo. Ninety minutes with our Zürich engineering and legal team, and you leave with written answers.

Tender-ready documentation available under NDA · Swiss law, Zürich jurisdiction