The two current infrastructure boundaries below are deliberately separated. Your workspace data — the records you create in DjeedX, the audit log, the backups — sits in Geneva, Switzerland, on Infomaniak Public Cloud. Infomaniak is an independent, ethical, Swiss-sovereign cloud and AI provider — renewable-powered, under Swiss data-protection law, and deliberately not a US hyperscaler. Djeed's own AI runs on Infomaniak's sovereign Swiss AI, so the intelligence layer stays in the same jurisdiction as the data. The public website at djeed.com is a separate Cloudflare surface. Its R2 object store uses the EU jurisdictional ring; Cloudflare KV, which stores lead submissions and rate-limit state, is globally replicated and has no per-namespace residency control. Anchor and Gateway boundaries are stated separately in the matrix above.
Side A · your data
DjeedX workspace · Geneva, Switzerland.
Every record you create in DjeedX, every member you invite, every file you upload, every audit-log entry, every backup — all of it lives on Infomaniak Public Cloud in Geneva. Infomaniak is an independent, ethical, Swiss-sovereign cloud and AI provider — renewable-powered and under Swiss data-protection law, not a US hyperscaler. The factory that produces base datasets runs on the same Swiss infrastructure. This is where your real data sits.
- · Postgres 16 + PostGIS — workspace records, audit log
- · Neo4j 5 + APOC — graph data, entity relationships
- · Redis — job queue, session cache
- · Object storage (CH) — backups, 30-day rotation
- · Infomaniak hosts the operating system and the network
- · Sovereign Swiss AI — Djeed's AI runs on Infomaniak, in Switzerland
Side B · the website
djeed.com · Cloudflare, EU jurisdiction.
The public site, methodology pages, and lead-capture forms run on Cloudflare Pages at the European edge. Storage on this side is small and operational: aggregate factory snapshots, lead-form submissions, and rate-limit counters. None of your DjeedX workspace data passes through here.
- · Cloudflare Pages — djeed.com static + edge functions
- · R2 (EU jurisdictional ring, Western Europe) — public site snapshots only
- · KV — lead submissions + rate-limit state (globally replicated; Cloudflare KV has no per-namespace residency option)
- · Turnstile + WAF — bot protection, request filtering
- · DjeedX sign-in routes through Cloudflare to the Swiss VM; nothing is stored on this side
┌──────── visitor ────────┐
│ │
▼ ▼
┌── Cloudflare edge (global) ──┐ djeedx.djeed.com sign-in
│ TLS 1.3 · WAF · Turnstile │ │
│ DNS · CDN · Bot mgmt │ │ (passes through,
└────────────┬──────────────────┘ │ not stored on CF)
│ │
SIDE B — website surface (Cloudflare) │
┌─────────────┬──────────────────┐ │
▼ ▼ ▼ │
djeed.com KV (global) R2 (EU jurisdiction) │
Pages leads + rate-limit factory stats │
│
SIDE A — your data (Infomaniak Geneva, CH) ◀──────┘
Infomaniak Public Cloud · Geneva, Switzerland
├─ Postgres 16 + PostGIS (workspace records, audit)
├─ Neo4j 5 + APOC (graph data)
├─ Redis (job queue)
├─ Object storage (CH) (backups, 30-day rotation)
└─ Caddy host (TLS termination)
Identity: Clerk (EU residency configured) — clerk.djeed.comResidency is product- and service-specific. DjeedX customer content stays inside its Swiss workspace boundary; public-site lead submissions use globally replicated Cloudflare KV. The applicable processing and transfer terms are documented in Privacy §04.