Hosting
Hosted in Switzerland
Every check runs on our GPUs in Switzerland. The API edge runs on Cloudflare, account data sits in Supabase’s Zurich region, and the tool calls you send are not stored. Here is exactly what runs where.
Where it runs
Three parts, three places
The path of one check, from your agent to the verdict.
- Step 1
Guard inference: our GPUs in Switzerland
The model that answers each check runs on GPUs we operate in Switzerland. The servers accept requests only from our gateway, authenticated with a shared secret.
- Step 2
API edge: Cloudflare
api.mcp-guard.ai and the website run on Cloudflare’s global edge. It terminates TLS close to your agent, checks the key and forwards the check to the GPUs over an encrypted connection.
- Step 3
Account data: Supabase, Zurich
Users, workspaces, API key hashes, credit balances and request metadata are stored in Supabase in the EU (Zurich) region.
What we keep
What is stored, and for how long
Not stored
Request payloads: the action, intent, user message, constraints, context and conversation. They are held in memory while the check runs and then discarded.
Kept 30 days
Request metadata: request id, time, endpoint, verdict, latency, credits charged, status. Used for billing, usage charts and debugging.
Kept while your account exists
Account data: email, workspace, a SHA-256 hash of each API key (never the key), balances and billing records. Card data stays with Stripe.
The legal detail is in the privacy policy, the DPA and the subprocessor list.
FAQ
Hosting questions, answered
Where are my tool calls processed?
Do you store the tool calls I send?
Does Swiss hosting cost extra?
Which other providers touch my data?
Does Swiss hosting make my agent safe or compliant?
Check your first tool call
The live demo runs on the same GPUs, free and without a key.