Security architecture & tenant isolation engineered in Switzerland.
We protect your school's customer rosters, instructor schedules, and financial records with enterprise-grade physical database isolation.
Built to protect your school's sovereignty.
Every design decision in our platform prioritizes data privacy, role confinement, and uninterrupted uptime during peak mountain seasons.
Dedicated Per-Tenant Schemas
Unlike platforms that pool thousands of businesses in one SQL table with simple query filters, Alpmate provisions physically segregated database schemas for each school. Cross-tenant leakage is prevented at the database driver level.
Server-Enforced RBAC
Permissions are strictly checked on the backend API before any record is served. A guide's mobile token cannot query company financial ledgers or other guides' personal earnings.
End-to-End Encryption
TLS 1.3 encryption with strict Perfect Forward Secrecy (PFS) in transit. All database volumes, backups, and media attachments are encrypted at rest using AES-256.
Swiss Tier IV Cloud Vault
Our primary infrastructure operates out of ISO 27001-certified Swiss datacenters in Zürich and Geneva, featuring biometric access controls and 2N redundant power grids.
Continuous Backups & PITR
Continuous Write-Ahead Logging (WAL) with daily automated snapshots stored in geographically distributed Swiss facilities, enabling point-in-time restoration within minutes.
Direct Merchant Settlements
Alpmate never stores credit card details or acts as an escrow intermediary. Card tokens are tokenized directly via Stripe Elements, minimizing PCI-DSS scope for operators.
Vulnerability Disclosure Program
We welcome responsible security research from ethical researchers and our operator community. If you discover a potential vulnerability within the Alpmate platform, please report it to our security engineering team immediately: