Compliance

What Swaylen supports — and does not claim.

Swaylen is designed to support responsible operation across jurisdictions. We are explicit about what is built, what is planned, and what we do not claim.

Certifications and claims — clearly labeled.

ItemStatus
SOC 2Not claimed
ISO 27001Not claimed
ISO 27701Not claimed
GDPR certificationNot claimed
EU-US Data Privacy FrameworkNot claimed
HIPAA / FedRAMPNot claimed

Swaylen does not claim any certification or compliance status it does not hold with verifiable evidence.

How Swaylen is designed for compliance-readiness.

Tenant isolation

Logical isolation between customer workspaces.

Access controls

Role-aware, least-privilege access.

Suppression & opt-out

Controls to respect recipient preferences.

Data provenance

Lineage where supported, for inspectability.

Auditability

Logs to support review.

Responsible automation

Human approval and policy boundaries.

Retention that respects control.

Swaylen follows a framework of collect, use, review, retain only as needed, and suppress or delete. Specific retention periods depend on product configuration and applicable policy; Swaylen does not publish placeholder durations it cannot back up.

How incidents are approached.

Swaylen follows detection, containment, investigation, remediation, and customer notification where required. Specific service-level commitments are only published where they genuinely exist.