Security & data¶
This is the most important page for anyone evaluating Teleutias: it answers the question "where does my data end up?".
The principle¶
All data processed by Teleutias remains within the client's infrastructure, in Switzerland. Documents, conversations, knowledge base and models reside on the local machine. No content is transmitted to external AI services — Swiss or foreign — neither during processing nor for training purposes.
What resides where¶
| Data | Where it lives | Who can access it |
|---|---|---|
| Uploaded documents (PDF, CSV, XML, …) | Local storage of the Teleutias machine | Authorised users, according to configured permissions |
| Conversations with the assistant | Local database on the machine | The individual user; the administrator according to the agreed policy |
| Company knowledge base | Local storage, indexed on the machine | Enabled assistants and users |
| Language models | Local storage (downloaded once during installation) | The system only |
What does NOT happen¶
- Documents are not uploaded to external AI clouds (OpenAI, Anthropic, Google, etc.).
- Content is not used to train any model, neither local nor third-party.
- No data is shared with Teleutias/OBS as a supplier, unless explicitly requested by the client during a support intervention.
- The machine is not reachable from the internet: it exposes no public services.
Access control¶
- Interface access with per-user authentication; each user only sees their own conversations.
- Assistants and knowledge bases can be restricted per group or per user (e.g. payroll documents visible only to those managing payroll).
- The client's administrator manages user creation, deactivation and permissions.
Remote access for support¶
If the client wishes, remote maintenance takes place over an encrypted point-to-point channel with these characteristics:
- can be enabled and revoked by the client at any time;
- permissions limited to the Teleutias machine only, not the company network;
- every intervention is agreed in advance.
Alternatively, maintenance can be carried out exclusively on-site.
Compliance¶
Teleutias' local approach is designed for contexts subject to confidentiality obligations: the Swiss nFADP/nLPD (new Federal Act on Data Protection), fiduciary professional secrecy, third-party payroll and accounting data.
Controller's responsibility
Teleutias provides an infrastructure that keeps data local, but overall compliance (legal bases, privacy notices, records of processing) remains the client's responsibility as data controller. On request, we can provide a technical description of the system for internal documentation purposes.
Backups¶
The backup strategy for the Teleutias machine is agreed with the client's IT and integrated into existing procedures (local backup or company NAS). Backups also remain within the client's infrastructure.