Compliance
What Swaylen supports — and does not claim.
Swaylen is designed to support responsible operation across jurisdictions. We are explicit about what is built, what is planned, and what we do not claim.
Status
Certifications and claims — clearly labeled.
| Item | Status |
|---|---|
| SOC 2 | Not claimed |
| ISO 27001 | Not claimed |
| ISO 27701 | Not claimed |
| GDPR certification | Not claimed |
| EU-US Data Privacy Framework | Not claimed |
| HIPAA / FedRAMP | Not claimed |
Swaylen does not claim any certification or compliance status it does not hold with verifiable evidence.
Designed to support
How Swaylen is designed for compliance-readiness.
Tenant isolation
Logical isolation between customer workspaces.
Access controls
Role-aware, least-privilege access.
Suppression & opt-out
Controls to respect recipient preferences.
Data provenance
Lineage where supported, for inspectability.
Auditability
Logs to support review.
Responsible automation
Human approval and policy boundaries.
Retention & deletion
Retention that respects control.
Swaylen follows a framework of collect, use, review, retain only as needed, and suppress or delete. Specific retention periods depend on product configuration and applicable policy; Swaylen does not publish placeholder durations it cannot back up.
Incident response
How incidents are approached.
Swaylen follows detection, containment, investigation, remediation, and customer notification where required. Specific service-level commitments are only published where they genuinely exist.
Legal
Not legal advice. Swaylen provides technology and controls designed to support responsible buyer discovery and outreach. Customers remain responsible for determining whether their use of the platform complies with applicable laws and regulations in their jurisdictions. Swaylen does not provide legal advice.