Questions and answers
The answers are worded as honestly as we would give them on the phone — including the points at which VERLON is not the right choice.
No, and we do not claim that either. Your request still goes to an AI provider — but in a version in which the sensitive details have been replaced by placeholders. Sensitive original data does not leave your environment; the provider receives only the pseudonymised version. Anyone who promises you "no data goes outside" while still using a language model in the cloud is not telling the truth.
No. Pseudonymisation is expressly not anonymisation. The personal reference does not disappear, because the mapping remains with you — otherwise we could not translate the answer back. Legally, it is a protective measure under Art. 32 GDPR or Art. 8 of the Swiss FADP.
Compliance always applies to a processing activity, never to software. We provide the technical measure and the evidence you need for your documentation — a record of replacements, retention periods, a data processing agreement. Responsibility for the processing remains with you. Any provider who sells you a compliance seal for a tool is selling you a feeling.
For lawyers, doctors, notaries and fiduciaries, the decisive question is not where the server is located, but whether the protected details leave the organisation at all. That is exactly where we start. For these organisations we recommend operation on their own premises or on a dedicated server — and we discuss the set-up with you beforehand, not afterwards.
Development and the company are Swiss. We agree the location of the installation with you — on your own premises, on a server dedicated to you, or in our environment. We give you the specific location in writing so that you can enter it in your processing documentation.
The technical part is done in a day. What follows takes longer: entering your master data and defining the rules for each department. Allow one to two weeks until everything runs smoothly — and a demo beforehand, so that you know what you are committing to.
Very little. Anyone who has worked with an AI chat before will get on with it straight away. The visible difference is the preview before sending — it shows what goes out. In our experience, that is precisely the moment when employees first understand what they have been sending until now.
Yes. You can store your own accounts with OpenAI, Anthropic or Google — you then continue to be billed there and pay us only for the software. Alternatively, we include usage in our invoice if you would rather not deal with it.
That is what the preview is for: before every send you see the original and the outgoing version side by side. If something is missing, you mark it and it is replaced from then on — in all future requests as well. You can also store your own terms so that the case does not arise in the first place.
The price depends on the operating model and the number of workstations. We state it in conversation as soon as it is clear what you need — and we state it in full, including the costs at the AI provider. We show usage costs per request so that they remain traceable.
Not to ISO 27001 or SOC 2 at present. We have built the measures these standards require into the product from the start — access reviews, logging, retention periods, change management — and can show them to you. A certificate cannot be brought forward; if your procurement strictly requires one, we will tell you so openly rather than keep you waiting.
Then you will probably build this yourselves — and you should. Our strength lies with organisations that have to meet the requirements without having a department for it.
Then an ordinary subscription is cheaper and simpler. VERLON is worthwhile as soon as real customer, client or patient data is involved.
That is a sensible scope, and we build expressly for it — the protection layer can be placed in front of an existing solution rather than replacing it. Talk to us about it.
Write to us. We answer ourselves, not from a set of stock replies.