Skip to main content
IP Copyright

Cloud Storage Isn't Custody: What Identity-Verified Escrow in Switzerland Actually Changes

In short

Dropbox, Google Drive, a shared company folder: all of them grant access to whoever holds the login, not to whoever is entitled to the file. Identity-verified escrow works differently. Recovery is tied to a KYC-verified person, held in Switzerland, independent of any cloud provider.

Cloud Storage Isn't Custody: What Identity-Verified Escrow in Switzerland Actually Changes — Swiss Trust Layer

A shared drive with the right login gets you the file. It does not get you a case for who was entitled to it. That gap sits quietly in the background of every engagement, every partnership, every cap table, right up until someone leaves, a relationship sours, or a password is the only thing standing between a team and a record they need. By then it is too late to fix how the file was stored. It was only ever custody by convenience, and convenience is not a claim.

What custody by convenience actually is

Cloud storage grants access to whoever holds the login. Dropbox, Google Drive, a shared company folder: none of them ask whether the person opening a file is the person entitled to it. They ask whether the password is correct. Most of the time that is fine, because most of the time nobody is disputing anything. The problem shows up in exactly the moments a finance or legal team cannot plan around: a founding partner leaves mid-dispute and still has the login. A contractor's account outlives the contract. A dissolved engagement leaves a shared drive with no clear owner and two former partners who each believe they should have it. A password manager fails, an employee departs without handing over credentials, or an account simply gets locked out after too many failed attempts, and suddenly a firm cannot reach files it has held for years.

None of that is a technology failure. It is what cloud storage was built to do: grant access based on possession of a credential. It was never built to answer "who is entitled to this," and treating it as if it does is exactly the gap that surfaces once a dispute makes the question matter.

What changes when recovery is tied to identity, not a login

Escrow on the Swiss Trust Layer register works differently, because it starts from a different question. Before a user can access or subscribe to escrow storage at all, they have to complete a full identity check, passport-verified, the same identity check used elsewhere on the register. Recovery is then tied to that verified person, not to whichever device or browser still happens to be signed in. If the credentials are gone, the identity is not. That is the entire shift: from "whoever has the password" to "whoever the register can verify is the right person," and it is what makes escrow a different kind of custody than a shared drive was ever designed to be.

The file itself is held in Switzerland, independent of any cloud provider. It sits alongside the rest of what the register already does: a sealed file with a qualified timestamp, a verified identity behind it, an ISCC code that identifies the work without exposing it, and content labels where they apply. We covered the full register in an earlier post, register once, carry the proof everywhere, and escrow is the piece of it built specifically for what happens after the file is sealed: who can still reach it, and on what terms, years after the person who sealed it first logged in.

What this does not promise

It is worth being precise about what identity-verified escrow covers today. What it costs, and which plan applies to which account, is a separate conversation, one this post is not going to have for you. What we can say plainly is the recovery claim itself: identity can be re-verified, online or in person through a KYC agent, and access to records and escrowed files restored. That is what escrow does, stated exactly as far as we can stand behind it, nothing added and nothing promised beyond it.

Think about the files a finance or legal team accumulates that nobody plans to fight over, until somebody does. Engagement records for a client relationship that ends badly. Supporting documents behind a cap table entry, drafted by someone who left the firm two years before a dispute surfaces. IP assignment evidence for work product built jointly, then contested once the joint venture dissolves. A partnership's founding documents, stored on a drive that both former partners can technically still open, neither of whom trusts the other not to have edited something. In every one of these, the question that eventually gets asked is not "was this file stored somewhere safe." It is "can you prove who was entitled to reach it, independent of who still happens to have the login." A shared drive cannot answer that question. An escrow record tied to a verified identity is built to. For work in this category, our IP and legal team page covers how sealing and escrow fit into a firm's existing evidence practice, not as a replacement for it.

Custody hygiene, not a one-time fix

None of this replaces the underlying agreements that establish who owns a file in the first place: engagement letters, IP assignment clauses, partnership agreements still do that work. What identity-verified escrow adds is a way to keep reaching the file itself once the people, the passwords, and the goodwill that used to hold a shared drive together have all changed. That is not a single decision made once. It is a habit worth building into how a firm stores the records it will eventually need to defend, before the dispute is the reason it looks for them.

Protect your work with Swiss Trust Layer AG

Seal your intellectual property with a court-proof e-Seal backed by Swisscom Trust Services.

Book a Free Demo

Related Articles

A Timestamp Proves a File Existed. It Doesn't Prove Who Made It. Now the Gap Is Closed.
IP & Copyright

A qualified electronic timestamp proves a file existed, unaltered, at a given moment. It has never proven who made it. MyCopyright closes that second gap by binding the sealed record to a passport-verified identity, so a dispute that turns on who, not just when, has an answer.

September 24, 2026Read Article →
Where the AI Copyright Cases Actually Stand, and What None of Them Decide for You
IP & Copyright

Four cases get lumped together as "the AI copyright cases." They are not one case, and none of them has ruled on whether training a model on your work without permission is infringement. Here is where Andersen, NYT v. OpenAI, Getty v. Stability, and Bartz v. Anthropic actually stand, and what creators can prove regardless of how or when any of them lands.

September 22, 2026Read Article →
The Moment Before an Engineer Walks Out the Door Is the Moment That Matters
IP & Copyright

IP risk does not start with a resignation letter. It concentrates in the weeks before, in private repos, personal emails, and unmerged branches nobody flagged as company records. Sealing source code, design docs, and prototypes as routine work, not just at launches, is what keeps a startup's ownership provable regardless of who leaves when.

September 21, 2026Read Article →
OpenAI, Google and Nvidia Back Content Credentials. That Still Isn't Evidence in Court
IP & Copyright

Content Credentials now ship from ChatGPT images, from professional cameras and soon from Chrome itself. That makes provenance readable at scale. It does not make a manifest something a court presumes to be accurate about who made a work and when.

September 17, 2026Read Article →
The AI Act Makes Your Opt-Out Their Obligation. It Still Isn't Your Proof
IP & Copyright

The EU AI Act tells model providers to go looking for your opt-out and to respect it once they find it. That obligation is real and it is theirs. What it can't do is answer the question a dispute puts to you: what did you make, and when.

September 15, 2026Read Article →