Skip to content
Sovereign AI. Swiss based.

We build agentic AI.
On sovereign Swiss infrastructure.

Caprilytics delivers strategy, engineering – and with Botster a platform for your business processes. All from Swiss hands, auditable down to the last step.

Why Caprilytics

AI that fits your company – not the other way round.

AI projects rarely fail on technology – they fail on strategy, integration and governance. We've built a model that tackles exactly these three points: products that solve them technically, and consulting that ensures the solution fits your company.

Strategy

A use-case portfolio with clear ROI and a roadmap that fits the business strategy. Individual pilots become an AI programme with measurable impact – no pilot graveyard.

Integration

Integration with knowledge base, ITSM, ERP and line-of-business systems. AI that knows your own systems – and works inside the production business, not next to it.

Governance

Audit trail, configurable autonomy limits and a governance framework for EU AI Act and revDSG. Every AI action is traceable – production use even in regulated industries like banking, pharma or healthcare.

Products

Botster. The digital colleague.

Botster is our product: an AI that works inside your systems instead of just giving answers. It takes over recurring tasks on its own – and logs every step, so you can trace what happened and when, at any time.

What Botster handles

Security monitoring: automatically checks the security of all security components on the network and reports anomalies.

Knowledge & policies: searches the company knowledge base and answers questions on internal policies and intranet content.

Morning briefing: condenses emails, industry news and competitor analyses into a daily briefing.

IT support: assists employees with troubleshooting and automatically opens a ticket when you can't solve a problem together.

Accounting: posts invoices automatically into your accounting software.

Your domain knowledge, our delivery: you know your processes – we build Botster to fit them.

Underneath sits the foundation: DocProzessor turns documents into structured data, Dokumentenarchiv keeps your ongoing correspondence audit-proof and findable – both directly usable by Botster.
Consulting

Only those who've built it themselves can give advice.

We don't sell a tool and disappear. We accompany you from the first strategy discussion through to production – and build software the way we run it ourselves. We made the shift from conventional to AI-assisted development in-house before guiding clients through it. Cybersecurity isn't an add-on module, but baked into every step.

We accompany you in three phases – from decision to independent operation.

Decide

Which use cases carry weight, which risks count, what the roadmap looks like. Before you invest.

Build

Architecture, integrations and governance that support production use, not just the pilot.

Enable

How your teams will develop, operate and work with AI going forward – so capability stays, not dependency.

Strategic AI direction

Strategy.
Roadmap.
Governance.

AI strategy for executive boards that look beyond pilots.

  • AI readiness assessment
  • Use-case portfolio with ROI estimate
  • Governance framework (EU AI Act, revFADP)
  • Build vs. buy decisions
  • Workshops for executive board
AI consulting

Architecture.
Compliance.
Integration.

Consulting that ends in architecture decisions – not in slides.

  • Architecture and technology consulting
  • Process analysis and automation design
  • Implementation of current governance frameworks (EU AI Act, revDSG)
  • Compliance and risk analysis
  • Threat modelling for AI agents (prompt injection, tool misuse, data exfiltration), ISMS integration, SIEM integration
  • Second opinion for ongoing initiatives
AI-assisted engineering

Pipeline.
Skills.
Coaching.

AI-assisted development is in production at our place. We bring this head start to your teams – security by design included.

  • Tool stack setup (Claude Code, IDE integrations)
  • AI agents in the GitLab/CI pipeline
  • Custom skills and integrations for Botster
  • Prompt and agent engineering training
  • Coaching and enablement of development teams
Differentiators

Three promises. Operational, not rhetorical.

What sets us apart from the market – not as a marketing message, but as an operational principle, proven in every project.

Sovereignty.

Sovereign by default. Frontier models when they make the difference.

By default, data stays in Switzerland: Swiss data centres, Swiss law. Where a frontier model (Claude, GPT, Gemini) makes the difference, we add it under control – with automatic PII masking before every outbound call. Full performance, controlled sovereignty.

Governance.

Governance down to the individual tool call.

Every AI action logged, every autonomy limit configurable. Audit trail down to the individual tool call, mapped to ISO 27001 Annex A, NIST CSF, revDSG, GDPR and EU AI Act – per product with risk classification. Audit readiness built in, not bolted on.

Guidance.

We don't just deliver – we run it with you.

Botster as lead product, DocProzessor and Dokumentenarchiv as foundation – and a team that also runs both in production. Strategy, integration and engineering from one source: no black box, we accompany you through production and beyond go-live.

Trust & Compliance

Trust is documentary.

We claim nothing about security or compliance we cannot evidence. The points below are the verifiable artefacts – locations, sub-processors, procedures, audit trails. Each one is tied to concrete vendors, standards or documents.

Location & sovereignty

Swiss data centres, Swiss law.

EKT AG (data centre, Frauenfeld TG) and Infomaniak (cloud services, Geneva) – both Swiss vendors, Swiss law, no US cloud export.

Via Infomaniak we access the Swiss sovereign model Apertus as well as open-source LLMs (Mistral, Llama).

In standard operation, customer data stays in Switzerland. Commercial third-party models – Anthropic, OpenAI, Google, xAI – are only added upon approval and under control: with PII masking before every outbound call, complete logging and contractually governed data processing.

Subprocessors

Who sees what – fully.

Vendor Function Location Legal basis
EKT AGHosting (data centre)Frauenfeld TGCH
Infomaniak SACloud, LLM inferenceGenfCH
Anthropic PBCLLM inferenceUSASCC + DPF
OpenAI, Inc.LLM inference (on demand)USASCC + DPF
Google LLCLLM inference (on demand)USASCC + DPF
xAI Corp.LLM inference (on demand)USASCC
Data protection

Privacy that earns the name.

We are controllers under Art. 5 lit. j revFADP; for EU data subjects also processors under Art. 3(2) GDPR. SCCs for third-country transfers. Privacy policy at datenschutz.html.

Security

Security-by-design, documented.

Zero trust with service JWT and OIDC; key management per tenant. Encryption at rest (Fernet) and in transit (TLS 1.3). Prompt-injection defence, permission sandbox per tool and egress control. Mapping to ISO 27001 Annex A and NIST CSF.

Audit trail

Every action. Every source.

Botster and DocProzessor log every AI action, tool call and source without gaps. Export as JSON, CSV or PDF. 10-year retention, GeBüV-compliant. Granularity: per API call including prompt, tool args, response.

EU AI Act

Risk classification per product.

Botster and DocProzessor: limited risk (transparency obligation, audit-trail obligation). High-risk only when used in HR / credit decisions / critical infrastructure – additional duties mapped accordingly.

Dokumentenarchiv: minimal risk.

Compliance enquiries
info@caprilytics.com
Security disclosure
security@caprilytics.com
About us

Founded 2018. Repositioned 2025.

Caprilytics, founded in 2018, grown from two decades of Swiss IT practice – today with a clear focus: agentic AI that withstands an audit.

Company
Market position

At home in the Swiss SME, with the architectural depth for the corporation. Young AI agencies have the methodology but lack the senior perspective. Established IT houses have the practice but rarely the modern AI architecture. We combine both – close to the SME to deliver pragmatically, and we know the processes and hurdles of regulated corporations.

How we work

We build software with AI, not just for AI. Our entire development process is laid out for AI-assisted engineering – planning, implementation, review, deployment. That lets us deliver, in small teams, the speed of larger software houses at higher code quality: every line goes through review and test before it goes live.

Specialisation

Framework-agnostic, specialised in Sovereign AI. We work with all common LLM and agent frameworks. Our focus is sovereign AI – which doesn't exclude other models but integrates them deliberately. Where we're really strong: handling agentic AI. Botster is the product where this expertise lives.

Cross-industry

Much separates our clients – one thing unites them: the security of their data.

  • Banking & insurance – knowledge systems that pass FINMA scrutiny
  • Pharma – clinical and regulatory process records
  • Manufacturing – quality and audit obligations across production and supply chain
  • Healthcare & public sector – revDSG requirements
  • Information-security teams – ISMS-compliant AI integration
  • IT service providers – AI in their own service portfolio
Team
Markus Bättig – Founder and CEO Caprilytics AG
Markus Bättig
Founder · CEO
LinkedIn
Marco Mata – Engineering Caprilytics AG
Marco Mata
Engineering
LinkedIn
Monica Knechtel – Communication Designer and Brand Manager Caprilytics AG
Monica Knechtel
Communication Designer · Brand Manager
LinkedIn
Frequently asked questions

Questions and answers.

What is Caprilytics?

Caprilytics AG is a Swiss provider of agentic AI and document intelligence, based in Lucerne and founded in 2018. It focuses on data-sovereign, audit-proof AI solutions for regulated companies – operated on Swiss infrastructure, governance-compliant and fully auditable.

What is Botster?

Botster is Caprilytics' platform for agentic AI – an AI that acts within the customer's systems instead of merely answering. Autonomous agents work independently under strict governance and log every action down to the individual tool call; autonomy limits are configurable, with mapping to ISO 27001 Annex A, NIST CSF and the revised Swiss FADP (revDSG).

Where is data processed at Caprilytics?

In standard operation, customer data stays in Switzerland – processed in Swiss data centres (EKT AG in Frauenfeld, Infomaniak in Geneva), under Swiss law. Commercial third-party models are enabled only on approval, with PII masking before every outbound call and contractually governed data processing.

Which AI models does Caprilytics use?

Sovereign models are the default. At its core is Caprilytics' own flagship: a self-hosted, in-house fine-tuned sovereign model based on Qwen, purpose-optimised for working with Botster. It is complemented via Infomaniak by the Swiss sovereign model Apertus and open-source LLMs such as Mistral and Llama. Frontier models (Anthropic Claude, OpenAI GPT, Google Gemini) are enabled selectively and declared transparently when they make the difference – framework-agnostic, specialised in sovereign AI.

Is Caprilytics compliant with the EU AI Act and the Swiss FADP (revDSG)?

Yes. Botster and DocProzessor are classified as limited risk under the EU AI Act (transparency and audit-trail obligations). In data protection terms, Caprilytics acts as controller under Art. 5 lit. j revDSG and, for EU data subjects, additionally as processor under the GDPR, with standard contractual clauses for third-country transfers.

How does Caprilytics ensure traceability and auditability?

Every AI action, every tool call and every source is logged without gaps – per API call including prompt, tool arguments and response. The audit trail can be exported as JSON, CSV or PDF and is retained for ten years in line with the Swiss GeBüV.

Which companies is Caprilytics for?

For companies to which their data matters – from Swiss SMEs to regulated groups in banking, insurance, healthcare, the public sector and industry. Botster gives them the freedom to use AI exactly where it delivers real value – with the confidence that security and compliance are never in question.

What services does Caprilytics offer beyond its products?

Alongside its three products (Botster, DocProzessor, Document Archive), Caprilytics supports customers in three phases: strategic AI direction for executive leadership, AI consulting for architecture and compliance, and AI-assisted engineering with coaching to empower the customer's own teams.

What is sovereign AI?

Sovereign AI refers to AI systems that run on self-hosted or sovereign models – independent of US cloud infrastructure. This keeps data within its own legal jurisdiction, such as Swiss data centres, and makes it possible to meet regulatory requirements like the Swiss FADP (revDSG) and the EU AI Act. Caprilytics specialises in sovereign AI: sovereign models are the default, and frontier models are only added transparently and on a declared basis.

What is agentic AI?

Agentic AI refers to AI systems that carry out tasks and make decisions autonomously, rather than merely responding – while logging every action. At Caprilytics, agentic AI agents operate under strict governance with a complete audit trail down to the individual tool call, keeping every decision traceable.

What are autonomous AI agents?

Autonomous AI agents are AI agents that carry out tasks without human intervention while documenting every operation – unlike reactive chatbots. Caprilytics runs them with configurable autonomy limits, governance at API-call granularity and data kept in Swiss data centres, with no dependency on US cloud LLMs.

What is AI governance?

AI governance is the structured control of AI systems within a company – policies, processes and technical controls for compliance, risk management and transparency. Caprilytics implements AI governance technically: a complete audit trail of all AI operations, control down to the individual API call, and documented compliance with the Swiss FADP (revDSG) and the EU AI Act.

What must AI agents comply with in Switzerland?

AI agents in Switzerland must comply with the revised Data Protection Act (revDSG/FADP) and – where the EU is involved – the EU AI Act. Caprilytics provides AI agents with a complete audit trail, data kept exclusively in Swiss data centres and self-hosted models with no dependency on US cloud LLMs – governance at API-call granularity included.

Contact

Reply by the next business day.

Reply within one business day. For NDA needs please request by email – we send a vetted template.

We process your details to handle your enquiry. Details under privacy.

Office
Caprilytics AG
Inseliquai 8
6002 Luzern · Schweiz