Skip to content
Trust · Security & sovereignty

You decide what Botster may know and do.

Botster runs on Swiss infrastructure. Roles, permissions and risk classes determine which knowledge is visible and which action is executed, approved or blocked.

01 · Autonomy

Controlled autonomy – the four levels

L0 · blocked The tool is not available.
L1 · propose Botster prepares the answer or the flow.
L2 · approve A person confirms before execution.
L3 · automatic A pre-approved, low-risk flow runs on its own.
Scenario · maintenance job L2
APPROVAL

The action waits in the approval queue. Only once an authorised person confirms does it run.

approval.requested → approval.granted
Example flow with curated test data. No real customer data.

Role, tenant and tool risk set the limits of each level. Approvals and tool calls remain traceable in the audit trail.

02 · Data protection

Swiss data protection, built in

Swiss PII detection for AHV (social security) numbers, IBANs and phone numbers Protection checks on inputs and tool results Implemented data export and deletion Tenant separation down to the database and two-factor authentication
03 · Sovereignty

Sovereignty means documented, not claimed

The default is Swiss infrastructure with a self-hosted model.

The data location, the models and the providers involved are documented per configuration. External models are only used where agreed. That supports compliance requirements, but does not replace a legal assessment of the individual case.

04 · Governance

Security is not a paid extra

These controls are included in every Botster package.

  • Audit trail
    immutable, exportable
  • Roles & tenant separation
    down to the database
  • Autonomy limits
    L0–L3, per tenant
  • Human approval
    for risky actions
  • PII detection & masking
    Swiss formats
  • Two-factor authentication
    for all accounts
Starter to Enterprise · no security upgrade · no extra licence Packages and terms →
Key statement

AI without an audit trail is not an enterprise product.

05 · FAQ

Common questions about security and sovereignty

Where is Botster data processed?+

Botster runs on Swiss infrastructure by default. The data location, the models used and the subprocessors involved are documented for the chosen configuration. External models are only enabled in a controlled way when this has been agreed and approved. That keeps it transparent which data is processed for which purpose by which provider.

How secure and traceable is Botster?+

Botster combines user permissions, tenant separation, risk classes and approvals with an audit trail for AI and tool actions. Sources, decisions, calls and results remain traceable. These capabilities support security, revFADP and EU AI Act requirements. The concrete regulatory classification depends on the area of use, however, and is not replaced by a blanket compliance promise.

Can Botster act on its own?+

Botster can carry out permitted tasks within configured limits. Depending on the tool, the risk and the autonomy level, a function stays blocked, is only proposed, needs human approval before execution, or may run automatically as a low-risk routine. That produces controlled autonomy rather than an agent with blanket access to company systems.