High-End Cloud & AI — so growth becomes predictable.

Beneath the business platform runs SM TECH: a scalable AI and cloud system that places many small bets automatically, doubles down on the winners and secures everything at the Cloudflare edge — encrypted all the way down to the database.

Cloudflare Edge EDGE Cloud application APP AI layer · Enhanced Success AI Data & automation DATA Security & access SEC
5Layers edge → data
300+Edge locations worldwide (CDN)
TLS 1.3Transport encrypted
AES 256Data at rest
0 DowntimeDeploys without interruption
24/7Operations & monitoring

Orientation values of the setup; edge locations per the CDN provider's network. Details depend on tier.

Full transparency & automation

No black-box marketing. Everything traceable.

You can see what's running at any time — not just in the monthly report. Numbers, appointments, documents and project status lie open in your portal. Automation handles the repetitive work; you stay in control.

portal.swiss-marketer.ch · Your cockpit Live

ⓘ Cockpit view is a mock-up · Demo data · No real customer data

Enquiries / month
42
▲ 24% vs. last month
Appointments booked
18
▲ 6 new
Pipeline open
CHF 112k
11 deals
Automations
24/7
active
Documents
3
newly shared
Project status
On Track
weekly review
Power Law · Automated bets

Not every bet wins. The portfolio wins predictably.

Marketing follows a power law: a few campaigns, audiences and messages drive most of the result. Most people make the mistake of spreading budget evenly. We do the opposite — many small bets, cut losers fast, scale winners relentlessly.

The power-law distribution

Sort every bet by result and this curve appears: a steep head (the big winners) and a long tail (many that barely carry). The goal isn't to make everything win — it's to find the head and shift everything there.

◄ Head: scale upTail: stop ►

The bet portfolio in action

Each field is a small, automated bet (campaign × audience × creative). The AI evaluates continuously, kills losers early and scales winners — without anyone having to stare at dashboards at night.

Loser — stopped Winner — scaled Top — fully built out
Enhanced Success AI model

Scales with your growth — not with your effort.

Classic setups get more expensive and slower as volume grows. The Enhanced Success model flips that: the more that runs, the more signals — and the better the decisions. The AI continuously learns what converts for you and shifts budget and attention there.

1
Collect signals

Clicks, replies, appointments, closings — every data point counts.

2
Spot patterns

The AI identifies which audience, message and timing actually convert.

3
Shift budget

Winners get more, losers are stopped — automatically.

4
Measure again

The result becomes the next signal. The loop starts over.

ⓘ The power law describes the structure, not a guarantee. Individual campaigns can lose — the method aims for a predictable portfolio result over time, depending on offer, market and budget. No guarantee of success.

Integrations & ecosystem

Your tool stack, connectable.

Swiss Marketer does not sit in isolation. Through open APIs, webhooks and standard connectors, the platform exchanges data with your existing tool stack — from the website to accounting. Through Make, Zapier or n8n, 2000+ tools are available.

Website
WordPress · Webflow · Framer
E-mail
Brevo · Mailchimp · Microsoft 365
Calendar
Google Calendar · Outlook · Cal.com
Ads
Meta Ads · Google Ads · LinkedIn Ads
ERP / Accounting
Abacus · Bexio · QuickBooks
CRM
HubSpot · Pipedrive · Salesforce
Messaging
WhatsApp Business · Slack · Teams
Automation
Make · Zapier · n8n
API / Webhooks
REST · GraphQL · HMAC
Identity / SSO
Entra ID · Google Workspace · Okta
Payment
Stripe · Twint · PostFinance
Document signing
Skribble · DocuSign · Adobe Sign

Directly on board: Make, Zapier, n8n, Webhooks, REST/GraphQL API — for no-code automations all the way to individual enterprise integrations.

CHF 4,950.00 · Invoice #2026-07121 · Due 30 days netⓘ Sample bill · Example values

Swiss QR-bill integrated — from contract to payment.

From contracts, proposals or completed jobs, a legally compliant Swiss QR-bill is generated automatically — including QR-IBAN, payment purpose and payee.

As soon as a proposal is accepted or a project is released, the system automatically generates the matching invoice with correct line items, VAT and payment terms.

  • Swiss QR-Bill compliant per SIX specifications
  • QR-IBAN and referenced payment traffic
  • Automatic reconciliation via Camt.054
  • Reminders on due or overdue dates
SM TECH Components

One stack. Five layers.

From the edge to the encrypted database, everything works together. Each layer has a purpose — speed, intelligence or protection — nothing is filler.

Production state · continuously hardened

Describes the production setup in its typical tier; details may vary by project and contract scope.

EDGECloudflare Edge

Global CDN, TLS termination, DDoS & bot defence in front of every request.

WAFDDoS protectionBot managementTLS 1.3
Specification
Edge / CDN
Global edge network in front of every request — WAF, DDoS protection, bot management, TLS 1.3.
WAFDDoS protectionBot managementHTTP/3
Origin shield
Origin lock: the application server accepts verified edge traffic only — direct access is rejected. Only verified edge traffic reaches the server — the rest: 403.
Header verification403 for direct access
APPCloud application

Business platform on scaling cloud infrastructure — auto-restart, health checks, zero-downtime deploys.

Auto-scalingHealth checksOrigin lockRate limits
Specification
App runtime
Zero-downtime deploys with health checks and auto-restart — releases without interruption, several times a week.
Health checksAuto-restartRolling releases
Circuit breakers
Rate limits & kill switches against abuse and cost explosions — per endpoint, per user, global.
Rate limitsDaily capsConcurrency limits
advisory_lock(host)
Concurrency
Critical sections — like appointment bookings — run behind database-level locks. Two simultaneous bookings on the same slot? Impossible.
AIAI layer · Enhanced Success

Lead research, prioritisation, follow-up copy, call transcription and an assistant with access to your data.

Latest Claude modelsRAGTool userole-aware
Specification
AI layer
Agents with guardrails: every AI tool runs under the user's permissions — never beyond. Transcripts with separate crypto keys.
RBAC toolsSeparate keys
DATAData & automation

Dedicated Postgres databases, daily backups, Make/webhook automations with retry on failure.

PostgresDaily backupsWebhooksIdempotency
Specification
Data layer
PostgreSQL with field-level encryption (AES-256) for sensitive data, daily backups and EU hosting.
AES-256 at restDaily backupsEU
webhook.idempotent
Lead safety
Incoming leads are processed idempotently: duplicate deliveries create no duplicates, transient errors lead to clean retries — never to silent loss.
SECSecurity & access

Encrypted secrets, signed webhooks, role-based access, session hardening and two-factor login.

AES-256HMACRBAC2FA
Specification
Identity
Zero-trust access: 2FA, hashed sessions with idle and absolute limits, role-based permissions — fail-closed.
2FARBAC fail-closedSession hashing
OPSOperations & compliance
Specification
Telephony
SIP over TLS — signalling encrypted, call notes and transcripts stored encrypted.
SIP-TLSEncrypted transcripts
Traceability
Central security audit log: security-relevant actions are recorded with request IDs — traceable instead of a black box.
Audit logRequest IDsMonitoring
Compliance
revDSG & GDPR — data processing agreement on request, data minimisation as a core principle.
revDSGGDPRDPA
Request Journey · The journey of a click
HOP 01
Browser
~0 ms
HOP 02
Edge
~10–50 ms
HOP 03
Origin lock
<1 ms
HOP 04
App core
~5–30 ms
HOP 05
Data
~1–15 ms
HOP 06
Response
total often <150 ms*

*Typical orientation values per station (excluding complex queries/AI runs); actual latencies depend on location, network and workload.

Cloudflare integration & security

Security is built in, not bolted on.

Every request passes through several protective layers before it ever touches your data. Cloudflare filters at the edge, an origin lock prevents bypass, internal access follows the Zero Trust principle, and inside everything is encrypted and sealed off by role.

Visitor → Cloudflare Edge

TLS-1.3 encrypted. The edge fends off DDoS attacks, checks for bots and blocks known attack patterns (WAF) before the request reaches the Switzerland-adjacent origin.

TLS 1.3DDoS defenceWAFBot score
Edge → Origin lock

Only Cloudflare may talk to the server: a secret header is injected at the edge; requests that try to bypass the server directly are rejected with a 403. That way the WAF can't be circumvented.

Origin lockShared-secret headertiming-safe
Application → Hardening

Strict Content Security Policy, rate limits (including dedicated budgets for expensive AI endpoints), security headers and input escaping against XSS. Every protective layer is tested and active.

CSPRate limitsHSTSnosniff
Data → Encryption & access

Sensitive values (credentials, transcripts) are encrypted with AES-256, webhooks are HMAC-signed, access is role-based (RBAC) and fail-closed. If you don't have clearance, you see nothing.

AES-256HMAC signatureRBAC fail-closedAudit log
Internal access → Zero Trust

No implicit trust from network or IP: internal access (CRM, admin, settings) follows the Zero Trust principle "never trust, always verify" — identity-based, with two-factor, least privilege and verification on every access. Optional, based on Cloudflare Zero Trust (ZTNA).

ZTNALeast PrivilegeContinuous VerificationDevice Posture

ⓘ Zero Trust access (ZTNA, Gateway, Device Posture) based on Cloudflare Zero Trust — as an optional module, scope depending on the project per individual technical review.

Auth & cryptography — methods
Two-factor login (2FA) — an extra factor via app or magic link; even a leaked password leaves the account protected.
TOTP · Magic link
Data encryption — credentials and transcripts are stored symmetrically encrypted with a separate master key.
AES-256-GCM
Signed webhooks — every automation message carries a cryptographic signature; forged payloads are rejected.
HMAC-SHA-256
Role-based access — each role sees only what it is allowed to — fail-closed. The client portal and internal CRM are strictly separated.
RBAC · Owner-scoped
Transport security — everything runs exclusively over HTTPS with enforced HSTS; no unencrypted channel.
TLS 1.3 · HSTS
Traceability — security-relevant actions land in a central audit log; every change is traceable.
Security audit log
Agentic Control — AI agents with guardrails

Specialised AI agents work in parallel — but never unchecked. Each agent has a clearly defined scope, budget limits and may only trigger critical actions after human approval.

Human approval Critical actions stay under control.

Purchases, contract changes, bulk sends or sensitive data queries are submitted for approval. The agent proposes; a human decides. Only after approval is the action executed. Who made which proposal, when was it approved and what was executed? Every step lands in the central audit log.

Role boundaries No agent beyond its rights.

Each agent sees only the data and tools assigned to its role. A sales agent gets no access to accounting — and vice versa. Fail-closed, like every other component.

Budget caps Cost explosions ruled out.

Daily, weekly and monthly limits for AI calls, API requests and ad spend. When a cap is hit, it stops automatically and notifies the team.

Coordination, not chaos The orchestrator keeps the overview.

A central orchestrator distributes tasks, detects conflicts between agents and ensures that results flow together consistently. Research, copy, appointment and analytics agents work side by side, exchange data only through defined interfaces and cannot overwrite each other.

Ready for technology that works for you?

See the technology live
High-end systems

High-end systems for demanding requirements.

For companies that need more than standard cloud: dedicated resources, individual SLAs, GPU clusters for your own AI models and an enterprise-grade deployment.

Private cloud & multi-region

Dedicated infrastructure in Switzerland or the EU — no shared resources, no noisy-neighbour issues, full control over data location and network.

Active-active or standby deployment across multiple regions — for global latency, regional resilience and disaster recovery to your specifications.

Your own H100 or B300 clusters for training, fine-tuning and inference — as an addition to SMT 6.1 or as dedicated AI infrastructure in your account.

Custom SLAs & enterprise onboarding

Response times, availability and escalation paths are defined in the contract — with defined credits, priorities and a direct point of contact.

A dedicated onboarding phase with discovery, IAM integration, training and go-live support. Your teams are productive before the first live day arrives.

24/7 monitoring & ISO/SOC alignment

Round-the-clock monitoring, alerting and incident response.

Architecture and processes are designed for ISO 27001 and SOC 2 — audit readiness included.

Ready for technology that works for you?

In the first call we show you the platform live — with your goals, your industry and a concrete plan for the first 60 days.