Infrastructure
Security & sovereignty

Swiss banking secrecy,
applied to your data.

End-to-end AES-256 encryption, keys held in Switzerland, replicated underground bunker, native nLPD and GDPR compliance. Your data rests in the most rigorous digital vault in Europe: confidentiality, neutrality, stability, discretion.

Swiss digital vault
End-to-end encryption

Three cryptographic layers. One key: yours.

Your data is encrypted before it leaves your device, stays encrypted on our servers, and is decrypted only on the client side. Even we, as operators, can't read it.

1. Encryption at rest

AES-256 GCM on every disk. Each volume block-level encrypted with a unique key. No reading possible if a disk is physically extracted.

2. Encryption in transit

TLS 1.3 with ECDHE and forward secrecy. No client/server communication can be observed, even via network interception. Ephemeral keys regenerated each session.

3. Client-side encryption

VAULT CUSTOM plans: client-side encryption before send. Your data arrives already unreadable. Only you hold the keys. Absolute confidentiality.

Key management

Certified HSM, keys in Switzerland, never out.

Your cryptographic keys are generated and held inside Hardware Security Modules (HSM) certified FIPS 140-2 level 3, physically sealed in Switzerland. No key ever leaves their enclosure.

  • HSM FIPS 140-2 level 3
  • On-site generation, never exported
  • Programmable automatic rotation
  • Bring Your Own Key (BYOK) optional

Bring Your Own Key (BYOK)

You can entrust us with your own cryptographic keys generated by your internal HSM (Thales, Utimaco, Entrust, Microsoft, etc.). We encrypt with them, never holding a persistent copy.

Hold Your Own Key (HYOK) available: keys never leave your infrastructure. AlpiVault encrypts via your HSM in pull mode.

The bunker, in numbers

  • Tier 3 datacenter (uptime 99.982%)
  • Certified Swiss civilian bunker
  • Inter-canton geographic replication
  • N+1 redundancy: power, cooling, fiber
  • Multi-factor biometric access control
  • 24/7 video surveillance, locally archived
  • Inert gas fire detection
  • Designed to resist EMP, earthquakes, intrusions
Physical hosting

Your data, deep in Helvetic rock.

AlpiVault operates inside certified Swiss civilian bunkers originally designed to resist major catastrophes. Climate-controlled rooms with redundant power, biometric access, locally-archived video surveillance.

The same tradition that secured nations' gold now secures your digital twins.

Helvetic legal framework

Native compliance, no asterisk.

Swiss-incorporated company, operated in Switzerland, billed in CHF. Jurisdiction: Lausanne. Native compliance with the most demanding regulatory frameworks — for clients based anywhere in the world.

FrameworkAlpiVault statusGuarantee
nLPD (Swiss law)Native complianceFederal Act on Data Protection — applies by right.
GDPRCompliantDPA provided, processing register, DPO reachable, data subject rights guaranteed.
ISO 27001AlignedInformation security management system — procedural alignment.
Sovereignty100% SwissCompany, team, datacenter, bunker, legal, billing: fully in Switzerland.
Independent auditAnnualPenetration tests by trusted Swiss third party, report available under NDA.
Reversibility planProvidedYour data exits in open formats (JSON, CSV, IFC, PDF, etc.).
Defense in depth

Six layers of protection. One promise.

1. Physical

Tier 3 datacenter + certified bunker. Biometric access, 24/7 video surveillance, inert fire detection, security airlocks.

2. Network

Multi-layer anti-DDoS, strict network segmentation, IP whitelisting, site-to-site VPN, real-time monitoring.

3. Data

AES-256 at-rest, TLS 1.3 in-transit, BYOK/HYOK available, daily encrypted backups, tested restoration.

4. Identity

SAML/OIDC SSO, MFA mandatory for sensitive roles, fine-grained permissions, complete audit trail, credential rotation.

5. Compliance

Native nLPD and GDPR, DPA provided, contractual reversibility plan, processing register, reachable DPO.

6. Operational

Human Swiss support, optional contractual SLA (120 CHF/month), security audit available, business continuity plan ready.

Going further

Documentation, audit, DPA — on request.

We provide on request: nLPD/GDPR DPA, architecture diagram, annual audit report, business continuity plan, subcontractor registry, compliance attestations.