Security monitoring: automatically checks the security of all security components on the network and reports anomalies.
Caprilytics delivers strategy, engineering – and with Botster a platform for your business processes. All from Swiss hands, auditable down to the last step.
AI projects rarely fail on technology – they fail on strategy, integration and governance. We've built a model that tackles exactly these three points: products that solve them technically, and consulting that ensures the solution fits your company.
A use-case portfolio with clear ROI and a roadmap that fits the business strategy. Individual pilots become an AI programme with measurable impact – no pilot graveyard.
Integration with knowledge base, ITSM, ERP and line-of-business systems. AI that knows your own systems – and works inside the production business, not next to it.
Audit trail, configurable autonomy limits and a governance framework for EU AI Act and revDSG. Every AI action is traceable – production use even in regulated industries like banking, pharma or healthcare.
Botster is our product: an AI that works inside your systems instead of just giving answers. It takes over recurring tasks on its own – and logs every step, so you can trace what happened and when, at any time.
Security monitoring: automatically checks the security of all security components on the network and reports anomalies.
Knowledge & policies: searches the company knowledge base and answers questions on internal policies and intranet content.
Morning briefing: condenses emails, industry news and competitor analyses into a daily briefing.
IT support: assists employees with troubleshooting and automatically opens a ticket when you can't solve a problem together.
Accounting: posts invoices automatically into your accounting software.
Your domain knowledge, our delivery: you know your processes – we build Botster to fit them.
We don't sell a tool and disappear. We accompany you from the first strategy discussion through to production – and build software the way we run it ourselves. We made the shift from conventional to AI-assisted development in-house before guiding clients through it. Cybersecurity isn't an add-on module, but baked into every step.
We accompany you in three phases – from decision to independent operation.
Which use cases carry weight, which risks count, what the roadmap looks like. Before you invest.
Architecture, integrations and governance that support production use, not just the pilot.
How your teams will develop, operate and work with AI going forward – so capability stays, not dependency.
Strategy.
Roadmap.
Governance.
AI strategy for executive boards that look beyond pilots.
Architecture.
Compliance.
Integration.
Consulting that ends in architecture decisions – not in slides.
Pipeline.
Skills.
Coaching.
AI-assisted development is in production at our place. We bring this head start to your teams – security by design included.
What sets us apart from the market – not as a marketing message, but as an operational principle, proven in every project.
By default, data stays in Switzerland: Swiss data centres, Swiss law. Where a frontier model (Claude, GPT, Gemini) makes the difference, we add it under control – with automatic PII masking before every outbound call. Full performance, controlled sovereignty.
Every AI action logged, every autonomy limit configurable. Audit trail down to the individual tool call, mapped to ISO 27001 Annex A, NIST CSF, revDSG, GDPR and EU AI Act – per product with risk classification. Audit readiness built in, not bolted on.
Botster as lead product, DocProzessor and Dokumentenarchiv as foundation – and a team that also runs both in production. Strategy, integration and engineering from one source: no black box, we accompany you through production and beyond go-live.
We claim nothing about security or compliance we cannot evidence. The points below are the verifiable artefacts – locations, sub-processors, procedures, audit trails. Each one is tied to concrete vendors, standards or documents.
Init7 (data centre, Glattbrugg ZH) and Infomaniak (cloud services, Geneva) – both Swiss vendors, Swiss law, no US cloud export.
Via Infomaniak we access the Swiss sovereign model Apertus as well as open-source LLMs (Mistral, Llama).
In standard operation, customer data stays in Switzerland. Commercial third-party models – Anthropic, OpenAI, Google, xAI – are only added upon approval and under control: with PII masking before every outbound call, complete logging and contractually governed data processing.
| Vendor | Function | Location | Legal basis |
|---|---|---|---|
| Init7 AG | Hosting (data centre) | Glattbrugg ZH | CH |
| Infomaniak SA | Cloud, LLM inference | Genf | CH |
| Anthropic PBC | LLM inference | USA | SCC + DPF |
| OpenAI, Inc. | LLM inference (on demand) | USA | SCC + DPF |
| Google LLC | LLM inference (on demand) | USA | SCC + DPF |
| xAI Corp. | LLM inference (on demand) | USA | SCC |
We are controllers under Art. 5 lit. j revFADP; for EU data subjects also processors under Art. 3(2) GDPR. SCCs for third-country transfers. Privacy policy at datenschutz.html.
Zero trust with service JWT and OIDC; key management per tenant. Encryption at rest (Fernet) and in transit (TLS 1.3). Prompt-injection defence, permission sandbox per tool and egress control. Mapping to ISO 27001 Annex A and NIST CSF.
Botster and DocProzessor log every AI action, tool call and source without gaps. Export as JSON, CSV or PDF. 10-year retention, GeBüV-compliant. Granularity: per API call including prompt, tool args, response.
Botster and DocProzessor: limited risk (transparency obligation, audit-trail obligation). High-risk only when used in HR / credit decisions / critical infrastructure – additional duties mapped accordingly.
Dokumentenarchiv: minimal risk.
Caprilytics, founded in 2018, grown from two decades of Swiss IT practice – today with a clear focus: agentic AI that withstands an audit.
At home in the Swiss SME, with the architectural depth for the corporation. Young AI agencies have the methodology but lack the senior perspective. Established IT houses have the practice but rarely the modern AI architecture. We combine both – close to the SME to deliver pragmatically, and we know the processes and hurdles of regulated corporations.
We build software with AI, not just for AI. Our entire development process is laid out for AI-assisted engineering – planning, implementation, review, deployment. That lets us deliver, in small teams, the speed of larger software houses at higher code quality: every line goes through review and test before it goes live.
Framework-agnostic, specialised in Sovereign AI. We work with all common LLM and agent frameworks. Our focus is sovereign AI – which doesn't exclude other models but integrates them deliberately. Where we're really strong: handling agentic AI. Botster is the product where this expertise lives.
Much separates our clients – one thing unites them: the security of their data.
Reply within one business day. For NDA needs please request by email – we send a vetted template.