top of page

Security at Swell

Your customer data powers everything Swell does. Protecting it is our first commitment, built into how we design, build, and operate the platform.

​

OUR SECURITY COMMITMENTS

 

Data protection by default. Customer data is encrypted in transit (TLS 1.2+) and at rest. Each customer's data is logically isolated, and personally identifiable information is automatically detected and handled with additional safeguards.

 

Least-privilege access. Access to production systems and customer data is restricted to authorized personnel with a documented need, protected by multi-factor authentication, and reviewed on a recurring schedule.

 

Vetted people and processes. Every employee and contractor with access to customer data completes background screening, signs confidentiality agreements, and receives security awareness training.

 

Continuous monitoring. Our infrastructure and security controls are monitored continuously, with automated alerting for threats, anomalies, and misconfigurations.

 

Independent verification. We are undergoing a SOC 2 Type II audit with an independent audit firm, with continuous compliance monitoring in place year-round.

 

Transparency and accountability. Our AI is explainable by default, with a full audit trail of agent actions and human-in-the-loop controls for consequential decisions.

INFRASTRUCTURE

 

Built on trusted infrastructure

Swell runs on enterprise-grade cloud infrastructure (AWS and Google Cloud) with hardened configurations, network-level protections, automated threat detection, and point-in-time recovery for production data. Critical data is replicated across geographic regions for disaster recovery, and audit logs are retained for a minimum of one year.

AI AND YOUR DATA

 

Responsible AI, grounded in your data

  • We do not use your personal information to train or improve our models

  • Your data is never used to train models for other customers

  • Every agent action is logged and explainable

  • Human-in-the-loop controls keep your team in charge

COMPLIANCE

 

Compliance

SOC 2 Type II audit in progress with an independent auditor. Our controls are continuously monitored through a dedicated compliance platform. To request our security documentation or audit report when available, contact us at security@swell.ai.

REPORT A SECURITY CONCERN

 

Report a security concern

If you believe you have found a security vulnerability, or have any concern about the security of your data, contact us at security@swell.ai. Reports go directly to our security team, led by our CTO, and we acknowledge every report.

bottom of page