- ThurWiki
- Security
Your knowledge stays in Switzerland.
A company wiki holds what makes a company what it is: its procedures, its customers, its prices, its credentials. That is why ThurWiki runs on ThurData's own infrastructure in Switzerland, with a sign-in you can take seriously and a watchman that spots attacks early, reports them and fends them off.
A data centre in a bunker.
ThurData runs ThurWiki in a former Swiss army bunker in Siegershausen in Thurgau: uninterruptible power supply (UPS), emergency power, protection against electromagnetic pulses (EMP), our own hardware. Pages, attachments and database stay exclusively in Switzerland. The US CLOUD Act (an American law giving US authorities access to data held by American providers, including abroad) does not apply. No tracking, and one contact with a name.
More about our data centre →What "Swiss data sovereignty" actually means with us.
A Swiss company, our own hardware
ThurData GmbH, Siegershausen TG. No US parent, no rented cloud. Requests from foreign authorities go through Swiss authorities and Swiss courts.
No tracking, and no outside services you did not switch on yourself
No analytics scripts, no fonts from other people's servers. draw.io and the thumbnails of the image search also run over our own server, so that no third party learns who is looking at what. Only what you connect outside the house yourself goes there: questions to an AI provider, notifications to WhatsApp or Telegram, search terms to web and image search.
One contact with a name
For questions about data protection, in an incident, on a request from an authority: you speak to a person at ThurData, not to a form in another time zone.
A sign-in you can take seriously.
- Two-factor sign-in: on top of the password comes a code generated by an app on the phone, Microsoft or Google Authenticator for instance. Every user can switch it on for their own account.
- Security keys (WebAuthn): the sign-in is confirmed by a small device such as a YubiKey, or by a fingerprint or face through Windows Hello and Touch ID. The key is bound to the address of the wiki; a fake sign-in form (phishing) at another address gets nothing.
- Signing in only from particular places: for an account you can record which internet addresses it may sign in from – only from the company network, say. Where nothing is recorded, it stays as before: from anywhere. Only an administrator can enter this, and nobody can lock themselves out with it.
- SSO through your company account (single sign-on: one login for every program), included in the Enterprise package: over the common protocols OpenID Connect or SAML 2.0 with Microsoft Entra ID, Google Workspace or your own company login system. Signing in with a password remains available to everyone alongside it, as a lifeline should the login service fail. When somebody leaves, the wiki administrator therefore also locks their account in the wiki.
- Protection against password guessing. Accounts are locked temporarily after too many failed attempts, not permanently: a permanent lock would be an invitation to paralyse other people's accounts on purpose.


A watchman that spots attacks.
The intrusion detection counts unusual behaviour. It spots attacks early, reports them and fends them off. It also sees distributed attempts in which each individual address looks harmless.
- Spotting. Unknown accounts, rejected requests, patterns in what is typed, attempts from many addresses at once.
- Fending off. Addresses are blocked temporarily, hijacked sessions are declared invalid.
- Reporting. The wiki administrator sees the picture in the administration and is notified when needed.
- Country restrictions when a wiki should only be reachable from certain countries.

What holds on the inside.
No route into somebody else's wiki.
Which wiki somebody sees is determined solely by their sign-in, never by something in the address bar or in the request. That way even a programming mistake in a single place can lead nobody into another company's wiki.
Access for programs is bound to a place.
An API key is access for another program – an account without a person. It too gets a list of permitted addresses, and that list is checked on every single request, not just once. If a key suddenly turns up from a foreign network, the watchman sees it.
Secrets encrypted, never shown again.
Access keys for the connectors (the connections to your other programs), passwords for calendars and mailboxes, API keys for your own programs: stored encrypted and, once saved, never shown again, neither in the interface nor through the API.
Everything logged, under a name.
Every change to pages, rights, users and access appears in the log, with person, time and origin. Including what an API key or the AI assistant does.
The search gives nothing away.
Only what you may see is found. A space somebody has not been given access to does not turn up among their hits, not even as a title. A page title often gives away enough.
The AI has only your rights.
The assistant sees what the signed-in person sees, and writes only with permission. For confidential company matters, a model in your own house; for that the address of your server has to be entered, otherwise the access cannot be saved. That way no question ends up at an outside service by accident.
Backups and versions.
Every page carries its complete history, and even an accidental restore can be undone; deleted things lie in the recycle bin. On top of that we back up the whole installation.
Questions about security and data protection
Where is ThurWiki's data stored?
In Switzerland, on infrastructure owned by ThurData GmbH in a former Swiss army bunker in Siegershausen in the canton of Thurgau, with a UPS, emergency power and EMP shielding. Pages, attachments and database never leave Switzerland. Swiss law and Swiss data protection law apply.
Is ThurWiki subject to the US CLOUD Act?
No. ThurData is a Swiss company with no US parent, and it owns the infrastructure itself; the US CLOUD Act does not apply. Requests from foreign authorities go through Swiss authorities and Swiss courts. Only what you connect outside the house yourself goes there: questions to an AI provider, notifications to WhatsApp or Telegram, search terms to web and image search.
How do users sign in?
With a user name and password, optionally with two-factor sign-in and a security key (WebAuthn), or, in the Enterprise package, through the company account by SSO: OpenID Connect or SAML 2.0 with Microsoft Entra ID, Google Workspace or the company's own login system. Signing in with a password remains available even with SSO. Accounts are locked temporarily after too many failed attempts.
Can we decide which places somebody may sign in from?
Yes. For every account you can record which internet addresses signing in is allowed from – only from the company network, say, or additionally from a branch office's network. Where nothing is recorded, "from anywhere" applies, as before. The same works for an API key, that is, access for another program; there it is checked on every single request, not just once at sign-in. Only an administrator can enter this, and only for other people – not for themselves in their own profile. Anyone who would lock themselves out this way gets an error message instead of a lock-out.
What does the intrusion detection do?
A watchman spots attacks early, reports them and fends them off. It counts unusual behaviour: unknown accounts, rejected requests, patterns in what is typed, distributed attempts from many addresses. It blocks addresses temporarily, invalidates hijacked sessions and reports what it sees. A wiki can additionally be restricted to particular countries of origin.
Who at ThurData can read our content?
Technically the administrators of the installation, as in any operated system. Organisationally the rule is: access only to fix a fault and at your request, logged. With you we conclude a data processing agreement under Swiss data protection law.
Questions about data protection? Give us a call.
We answer them before you order a wiki. On request, with our data processing agreement to read through.