Hosting

Hosted in Switzerland

Every check runs on our GPUs in Switzerland. The API edge runs on Cloudflare, account data sits in Supabase’s Zurich region, and the tool calls you send are not stored. Here is exactly what runs where.

1111010001000010011101100010110110001011001111100100110001000100111101111100101110000001001001110011110101001010010000011011100000111000100001010000101100111011110010110001111011110000010101011111000111011110011110011011001011001001001110001100001101000101011110001111001101011100000010111001000000100101100101000101101110111010110001001100010001000101011111001100011101110111001101110110001000110101000001011010001011000011110001000000000110111111010100000001000011010001011101111101100011110010110110111110010101101110100110011000010110111110101110001101100000100101001011101000011110110111000100011110101011110101001100010111001001100000100010000110001110001001110101100111001101101011010111001101101111100111011111111001011101001110000100011100000010001110111110110000101100000100000110000110100101111101010110011101110011001010000010100101000101111001011101011100110100010010101011101100000001101001100111101100010111010100110110101111011011111111111101101000001110010101011101111010001000110010001111110001010011010101
processed in Switzerland · 0 bytes of content stored

Where it runs

Three parts, three places

The path of one check, from your agent to the verdict.

  1. Step 1

    Guard inference: our GPUs in Switzerland

    The model that answers each check runs on GPUs we operate in Switzerland. The servers accept requests only from our gateway, authenticated with a shared secret.

  2. Step 2

    API edge: Cloudflare

    api.mcp-guard.ai and the website run on Cloudflare’s global edge. It terminates TLS close to your agent, checks the key and forwards the check to the GPUs over an encrypted connection.

  3. Step 3

    Account data: Supabase, Zurich

    Users, workspaces, API key hashes, credit balances and request metadata are stored in Supabase in the EU (Zurich) region.

What we keep

What is stored, and for how long

  • Not stored

    Request payloads: the action, intent, user message, constraints, context and conversation. They are held in memory while the check runs and then discarded.

  • Kept 30 days

    Request metadata: request id, time, endpoint, verdict, latency, credits charged, status. Used for billing, usage charts and debugging.

  • Kept while your account exists

    Account data: email, workspace, a SHA-256 hash of each API key (never the key), balances and billing records. Card data stays with Stripe.

The legal detail is in the privacy policy, the DPA and the subprocessor list.

FAQ

Hosting questions, answered

Where are my tool calls processed?
On our GPUs in Switzerland. The request passes through Cloudflare’s edge on the way in and out; Cloudflare forwards it over TLS and does not store its content.
Do you store the tool calls I send?
No. Payloads are processed in memory and not written to a database or log. We keep request metadata (ids, verdict, latency, credits) for 30 days.
Does Swiss hosting cost extra?
No. There is one price per check, wherever you call from.
Which other providers touch my data?
Cloudflare (edge and website), Supabase (account database, Zurich region), Stripe (payments) and our email provider for account emails. The full, current list is on the subprocessors page.
Does Swiss hosting make my agent safe or compliant?
No. Hosting location is about where data is processed. The guard itself reduces the risk of harmful tool calls but does not guarantee safety, and compliance depends on your whole system. We hold no SOC 2 or ISO certifications today.

Check your first tool call

The live demo runs on the same GPUs, free and without a key.