Take advantage of state-of-the-art language models (Large Language Models, LLM) without transferring sensitive data to providers abroad. AlpineAI AG operates all of its models on its own hardware in Swiss data centers, which are certified to ISO 27001:2022 and designed to meet the requirements of the healthcare, research, and government sectors.

Certified Infrastructure in Swiss Data Centers
AlpineAI AG runs its language models on its own hardware in Swiss data centers. The AlpineAI platform and the associated data are hosted by RIZ AG at two geographically separate, georedundant locations. GPU inference—that is, the actual execution of the language models—takes place at Green Datacenter AG and at the Rechenzentrum Ostschweiz (RZO). All three partners are ISO 27001-certified and provide pure colocation space: The servers are owned, configured, and operated by AlpineAI AG, and the operators have no logical access to virtual machines, operating systems, or data.
Certified to ISO 27001 and VDSZ
AlpineAI AG is certified to ISO 27001:2022, the international standard for information security management systems, as well as to VDSZ (Ordinance on Data Protection Certifications, SR 235.13). Both certificates were issued by SQS, the Swiss Association for Quality and Management Systems. The VDSZ certification goes beyond information security and confirms that the data processing itself is designed in compliance with data protection regulations. The data center partners RIZ AG, Green Datacenter AG, and Rechenzentrum Ostschweiz (RZO) are also certified to ISO 27001. For you, this means externally verified information security and a risk management system that is regularly audited.
Full Compliance with DSG and GDPR
AlpineAI AG implements the requirements of the Swiss Data Protection Act (DSG) and the European General Data Protection Regulation (GDPR) through its General Terms and Conditions (GTC) and Data Processing Agreement (DPA). As a Swiss company, we offer you a legally compliant foundation for the use of generative AI. The AlpineAI platform is designed to process even particularly sensitive personal data, such as patient or citizen data, in plain text. The solution has been reviewed in several cantons as part of a data protection impact assessment (DPIA).
Isolated environment with strict access governance
Your processes run in an isolated environment on hardware owned by AlpineAI AG; your content is stored and processed in Switzerland. The Data Processing Agreement (DPA) limits processing to Switzerland and the European Economic Area (EEA), and all subcontractors are disclosed in Annex 3 of the DPA along with the purpose and location of processing. Access is granted via role-based access control (RBAC) and follows the principle of least privilege: Each person is granted only the permissions that are strictly necessary for their specific task. All individuals who process customer data are contractually bound to maintain confidentiality (Section 4.4 of the DPA).
Encryption with AES-256 and TLS
Your data is encrypted both during transmission and while stored. Content stored on AlpineAI AG’s own hardware in Swiss data centers is encrypted using AES-256, the current standard for data at rest. Data is transmitted between your device and the platform exclusively via TLS. In addition, firewalls, network segmentation, multi-factor authentication for systems containing personal data, and regular penetration tests protect access. These measures are set forth in Annex 2 of the Data Processing Agreement (DPA).
Frequently Asked Questions About Security
AlpineAI AG stores and processes your content in Switzerland. AlpineAI AG operates the models on its own hardware in geographically redundant, ISO 27001-certified Swiss data centers operated by its partners RIZ AG, Green Datacenter AG, and Rechenzentrum Ostschweiz (RZO).
The application and data are operated by RIZ AG (ISO 27001) at two geographically redundant locations in Switzerland; GPU inference takes place at Green Datacenter AG and at the Rechenzentrum Ostschweiz (RZO), both of which are ISO 27001-certified and accessible exclusively via VPN. Both partners provide colocation space only: The hardware is owned by AlpineAI AG and is configured and operated by AlpineAI AG. There is no logical access to virtual machines, operating systems, or data; content data is always encrypted. Your data is therefore subject to the Swiss Data Protection Act (DSG) at all times and also complies with the requirements of the European GDPR. The Data Processing Agreement (DPA) limits processing to Switzerland and the EEA; all subprocessors are disclosed in Annex 3 of the DPA, along with the purpose and location of processing, and are contractually obligated to maintain the same level of protection.
The optional web search is an exception: If it is used, search query data is transmitted to an external search provider (Section 2.5 of the Terms and Conditions). It is subject to a three-step opt-in process and can be disabled at any time for the entire instance.
AlpineAI AG protects customer data through a multi-layered security architecture consisting of network segmentation, encryption, access controls, and continuous monitoring.
The platform is operated in Swiss data centers; the language models run on hardware owned by AlpineAI AG. Stored data is encrypted using AES-256, and all data transmission is TLS-encrypted. Access to systems containing personal data at AlpineAI AG is protected by multi-factor authentication, granted on a role-based basis, and regularly reviewed and audited. In addition, there are firewalls, network segmentation, regular penetration tests and vulnerability assessments, as well as an established process for responding to security incidents. These measures are set forth in Annex 2 of AlpineAI AG’s Data Processing Agreement (DPA).
AlpineAI AG processes customer data exclusively for the purpose of providing the agreed-upon service and in accordance with the customer’s documented instructions; this is subject to any legal obligation to process the data for other purposes, which will be communicated to the customer in advance, to the extent permitted by law (Section 2.1 of the General Terms and Conditions). All persons who process customer data are contractually bound to maintain confidentiality (Section 4.4 of the General Terms and Conditions).
For data subject to official, professional, or other legal confidentiality obligations, a supplementary agreement regarding the processing of confidential data may also be entered into. Once signed, employees of AlpineAI AG and its subcontractors may access this data in plain text only on a need-to-know basis and only with the customer’s prior individual authorization, in the event of an unavoidable emergency affecting business continuity, or pursuant to an enforceable order from a competent Swiss authority. AlpineAI AG also takes appropriate measures to ensure that third parties do not gain plaintext access to confidential data.
No, AlpineAI AG does not use your data to train language models. What you enter is not fed back into the models and is not used for their further development (Section 4.4 of the Terms and Conditions).
Whatever you create using the platform belongs to you: AlpineAI AG makes no claim to intellectual property rights in it, and you may use the results without restriction as your own work products, distribute them internally, and share them externally (Section 4.4 of the Terms and Conditions). Your content remains on AlpineAI AG’s own hardware in Swiss data centers. Disclosure to third parties is limited to the subcontracted processors listed in Annex 3 of the General Terms and Conditions, who are contractually obligated to maintain the same level of protection.
No, prior anonymization or pseudonymization is not technically required to use the AlpineAI platform. The platform is designed to process personal data and data requiring special protection in plain text.
For data subject to official, professional, or other legal confidentiality obligations, AlpineAI AG enters into a supplementary agreement with corporate clients regarding the processing of confidential data. This agreement comprehensively governs plaintext access: Employees of AlpineAI AG and engaged subcontractors are granted access to confidential data in plaintext only on a need-to-know basis and only with your prior individual authorization, in the event of an emergency related to business continuity that cannot be delayed, or pursuant to an enforceable order from a competent Swiss authority. Third parties are not granted plaintext access. Services involving confidential data in plaintext may be provided exclusively in Switzerland. When using the application programming interface (API), requests and responses are neither stored nor logged. AlpineAI AG is prohibited from conducting abuse monitoring with plaintext access, as well as from using the confidential data for its own purposes, particularly for training purposes.
As the data controller, you decide whether you still wish to anonymize data in individual cases based on your legal basis and the purpose of processing; before entering particularly sensitive personal data, ensure that you have a valid legal basis, such as statutory authorization or valid consent.
AlpineAI AG is certified according to ISO 27001:2022 (Information Security Management System) and VDSZ (Ordinance on Data Protection Certifications, SR 235.13). Both certificates were issued by SQS (Swiss Association for Quality and Management Systems).
VDSZ certification goes beyond information security and confirms that the processing itself is designed in compliance with data protection regulations. AlpineAI AG’s infrastructure partners—RIZ AG and Green Datacenter AG—are also certified to ISO 27001. In addition, “swiss digital service +AI” and “swiss made software +AI” serve as labels of origin and quality—not as certifications. AlpineAI AG contractually implements the requirements of the Swiss Data Protection Act (DSG) and the EU GDPR through its General Terms and Conditions (GTC) and the Data Processing Agreement (DPA).
AlpineAI AG operates on a clearly defined contractual basis in accordance with Swiss data protection law and the EU GDPR. Customers accept the General Terms and Conditions (GTC) and enter into a Data Processing Agreement (DPA).
Under the Data Processing Agreement (DPA), you remain the data controller; AlpineAI AG acts as the data processor and processes your data in accordance with the General Terms and Conditions, the DPA, and your documented instructions (Section 1.1 of the DPA). For data subject to official, professional, or other legal confidentiality obligations, AlpineAI AG also provides a supplementary agreement for the processing of confidential data. The solution has been reviewed in several cantons as part of a data protection impact assessment (DPIA). All documents are publicly available:
•General Terms and Conditions (GTC)
•Data Processing Agreement (DPA)
•Supplementary Agreement for Confidential Data
Corporate customers can receive a countersigned copy by sending the signed General Terms and Conditions (AVV) to compliance@alpineai.ch. We will provide you with all the information needed for your processing inventory and for your own data protection impact assessment (DSFA) upon request.
Have further questions?