Security & Privacy
Last updated: July 2026
We hold our own platform to the standards we build for our clients. Here is how this site is secured and how we handle data — every claim below is verifiable in your browser's developer tools.
Privacy by design
This site uses no cookies and no third-party trackers. Analytics are cookieless and self-hosted on our own Swiss infrastructure, so no personal data leaves our control and no consent banner is required. Our practices align with the Swiss FADP and the EU GDPR.
Swiss data residency
The website and its backend run entirely on servers located in Zurich, Switzerland. Your data stays within Swiss jurisdiction — it is never processed on US or other non-Swiss infrastructure.
Encryption in transit
All traffic is served exclusively over HTTPS with a valid TLS certificate; plain HTTP requests are permanently redirected. HTTP Strict Transport Security (HSTS) with preload instructs browsers to only ever connect over encrypted channels.
Hardened by default
The site ships a strict Content-Security-Policy and a complete set of modern security headers (Permissions-Policy, cross-origin isolation, clickjacking protection). Containers run rootless, the attack surface is kept minimal, and public forms are rate-limited and protected against automated abuse.
Data minimization
The contact form collects only what is necessary to reply to you. Submissions are stored minimally and are not shared with advertising or profiling services. We do not sell data.
Responsible disclosure
If you discover a security issue, we want to hear from you. Report it to info@heldevia.ch — see our machine-readable policy at /.well-known/security.txt. We acknowledge reports and work to resolve valid issues promptly.