Security Policy

Last updated: March 24, 2026

Introduction

At Swifteq, protecting customer data is a core part of how we build and operate our products. We maintain a security program designed to protect the confidentiality, integrity, and availability of the systems and data our customers entrust to us.

Swifteq is SOC 2 Type II compliant. Our public Trust Center includes additional information about our controls, policies, and security posture.

This page is a high-level overview of our security practices and is intended to complement our Service Agreement, Data Processing Agreement, and Privacy Policy.

Infrastructure and Data Hosting

Swifteq services are hosted on Amazon Web Services (AWS) in Europe, with customer data stored within the EU. Our infrastructure is designed with security, resilience, and availability in mind.

Key measures include:

  • Encrypted data in transit using TLS 1.2 or higher
  • Encryption at rest using industry-standard controls, including AES-256 for protected data
  • Segmented cloud environments, tightly restricted network access, and hardened system configurations
  • Encrypted backups with defined retention periods and recovery procedures
  • Regular backup restoration tests and disaster recovery planning to support service continuity

Application and Access Security

We apply security controls throughout the software development lifecycle, from design through deployment and maintenance.

These controls include:

  • Secure development practices, code review, and version-controlled changes
  • Vulnerability scanning, patch management, and annual external penetration testing
  • Role-based access control based on least privilege and need-to-know principles
  • Multi-factor authentication for critical systems and strong password requirements
  • Logged, limited, and regularly reviewed access to production systems

Operational Security

We maintain formal policies and procedures covering incident management, risk assessment, access control, backup, business continuity, vendor management, and employee security awareness.

Our operational safeguards include:

  • Continuous monitoring of systems and security events
  • Defined incident response and escalation procedures
  • Regular risk assessments and ongoing remediation of identified issues
  • Security review and oversight of critical third-party providers
  • Security awareness and privacy training for employees and contractors
  • Device protection controls such as disk encryption, endpoint safeguards, and secure offboarding

Continuous Improvement

Security is an ongoing process. We regularly review and improve our controls to address changes in technology, threats, and regulatory expectations. Where appropriate, we test the effectiveness of our safeguards through access reviews, vulnerability assessments, restoration testing, and security audits.

For customers or partners who need more detailed information, including supporting documentation, please visit our Trust Center or contact us directly.