Trust and infrastructure

Built for the security team that signs off — not just the buyer who signs.

If you run a hospital, a regulated business, or a professional network, member data cannot live somewhere you do not fully trust — and your security team will ask hard questions before anyone adopts a new system. This page answers them up front: encryption, access control, hosting, audit logs, data residency, and compliance, laid out plainly. On expertshare, security is the foundation the platform is built on, not a feature bolted on after launch.

EU / Switzerland residency · audit-ready by default · DPA on request.

Our posture, before the detail

Three commitments your reviewers can hold us to.

Everything below this band is the evidence. These are the principles it adds up to — the answers a security review is really looking for.

  • Foundation, not feature

    Secure by default, not by tier

    Every control applies to every space at the baseline. There is no "secure plan" to upgrade into — encryption, access control, and audit logging are simply how the platform runs.

  • Your jurisdiction

    Data stays where your rules say

    EU and Switzerland residency options keep your knowledge, member records, and audit trails in the region your governance and your regulator require.

  • Yours, not ours

    You own the knowledge

    We run the storage, encryption, and access controls. The content, the members, and the access rules belong to you — expertshare is infrastructure, never an intermediary.

The register

Security engineered into every layer.

The controls below apply across every space on the platform — there is no "secure tier" you have to upgrade into. This is the baseline.

Encryption

All data encrypted in transit (TLS 1.3) and at rest (AES-256), with database-level encryption for sensitive fields. Your knowledge is protected on the wire and on disk, by default.

Access control

Granular role-based access inside every space, optional SSO (SAML / OIDC), and two-factor authentication available platform-wide. You decide precisely who sees what — open, registered, or paid — per space.

Hosting

EU and Switzerland data-residency options, so your data stays in the jurisdiction your governance requires. Hosted on certified Tier-III-grade infrastructure with daily encrypted backups and point-in-time recovery. We confirm the specific data-center provider, region, and uptime commitment in writing for your deployment — no guesswork, in your contract.

Audit logs

Every space records who did what and when in an immutable, exportable event trail — so when an auditor asks for evidence, you hand it over instead of reconstructing it under pressure.

Incident response

Documented response procedures, critical issues acknowledged within hours, and notification to affected organizations in line with GDPR and regulatory requirements. You are told what happened, fast, in writing.

Compliance

GDPR-aligned and Swiss DSG-aligned, with Data Processing Agreements available and healthcare deployments meeting sector-specific confidentiality requirements. Built for the regulated industries that anchor the ecosystem.

The line that matters

What is shared, and what is unmistakably yours.

A reviewer’s real question is rarely "is it encrypted?" — it is "what does running on shared infrastructure actually expose?" Here is the honest boundary, drawn line by line.

Dimension The shared platformYour space
Your content & members Provides the storage, encryption, and access controls underneath. Owned by you. Never visible to other organizations on the platform — not the content, not the member list, not the analytics.
Who decides access Enforces the rules; never sets them. You define who gets in — open, registered, or paid — per space, with role-based access and optional SSO.
Where data lives Offers EU and Switzerland residency, plus a fully isolated private deployment for organizations that need complete separation. You keep control of the jurisdiction — confirmed in writing for your deployment, accurate to your contract.
Our team’s access Reaches your data only on your explicit request, logged every single time, for a defined operational purpose. Yours by default. expertshare is infrastructure, not an intermediary that sits between you and your own data.
Cost of "secure" Encryption, audit logging, and access control are the baseline — not a premium tier. You get the full control set on day one. There is no security upgrade to buy into.
The infrastructure is ours. The knowledge, the members, the access rules are yours.

Data sovereignty and ownership

Your data stays where your rules say — and the knowledge stays yours.

Data residency is not an afterthought for the institutions and regulated businesses expertshare is built for — it is a precondition. That is why the platform offers EU and Switzerland hosting options, so the knowledge, member records, and audit trails inside your space remain in the jurisdiction your governance and your regulator require. For organizations that need complete separation from the shared public world, a fully isolated private deployment is available as well. Whatever the model, the principle holds: you keep control of where your data lives and who can reach it, and we document the specific region, provider, and recovery commitments in writing for your deployment.

Ownership runs on the same principle. We provide the storage, encryption, and access controls; you keep full ownership of the knowledge you publish, the members of your space, and how you configure access. Nothing about your space — its content, its member list, its analytics — is visible to other organizations on the platform, and our team accesses your data only on your explicit request, logged every single time, and only for a defined operational purpose. See how this plays out in practice in the compliance workflow and what it means for institutions.

Already trusted with the hard cases

Organizations that vet vendors for a living already run here.

The clearest security reference is not a badge — it is who already keeps their data on the platform. These organizations passed their own review before they adopted it.

  • Insel Spital

    A hospital’s data, in production

    The founding anchor of the healthcare vertical runs its continuing education on expertshare — patient-adjacent, regulated, and live, with the audit trail and access controls a clinical setting demands.

  • University of Bern

    Records that have to hold up

    Continuing education and certification records run on the same infrastructure, where the evidence has to survive scrutiny years after it was created.

  • RUAG · Credit Suisse

    Built to survive procurement

    Security-conscious, regulated enterprises publish to professionals beyond their walls without surrendering access control, residency, or ownership of their data.

Security review

What your reviewers will want to know.

  • Where is our data hosted, and can we keep it in our region?

    Yes. expertshare offers EU and Switzerland data-residency options, so your data stays in the jurisdiction your governance requires. We confirm the specific data-center provider, region, and recovery commitments in writing for your deployment — accurate to your contract rather than rounded for a webpage.

  • Can other organizations on the platform see our content or members?

    No. Your space is fully isolated — its content, member list, and analytics are never visible to other organizations on the platform. Our own team accesses your data only on your explicit request, logged every time, and only for a defined operational purpose. The infrastructure is shared; your knowledge and your members are not.
  • What compliance frameworks does expertshare align with?

    The platform is GDPR-aligned and Swiss DSG-aligned, with Data Processing Agreements available on request and healthcare deployments meeting sector-specific confidentiality requirements. We share detailed security documentation so your reviewers can assess it against your own framework, and we confirm specifics in writing rather than claiming certifications we cannot evidence.

  • How do you handle a security incident?

    Through documented response procedures: critical issues are acknowledged within hours, and affected organizations are notified in line with GDPR and regulatory requirements. You are kept informed of what happened and what was done, in writing — not left to find out on your own.

Responsible disclosure

Found something? Tell us first.

If you believe you have discovered a security vulnerability, we want to hear from you. Reach us through our Contact page with as much detail as possible. We aim to acknowledge valid reports within 48 hours and to work with you toward a fix.

Please do not publicly disclose a vulnerability before we have had the chance to investigate and remediate — responsible disclosure protects the organizations and professionals who rely on the platform.

Questions from your security team? Send them our way.

We publish detailed security documentation and provide a Data Processing Agreement on request. Ask, and we will send the docs your reviewers need and set up a call with someone who can answer the technical questions directly — no sales filter in between. Your space, your data: you own it, and expertshare is the infrastructure underneath, never an intermediary.