Security

Security by design, stated honestly.

Swaylen is designed with secure defaults, controlled automation, and clear boundaries. Where a capability is planned rather than live, we say so.

What Swaylen is designed to support.

Tenant isolation

Each customer workspace is logically isolated from other customers.

Authentication & authorization

Access is controlled and role-aware, with least-privilege behavior.

Encryption in transit

Traffic is encrypted in transit using industry-standard TLS.

Secure defaults

The product is designed to be safe by default, requiring explicit action to widen access.

Fail-closed controls

Automation does not act without explicit approval; permissions fail closed.

Auditability

Actions and changes are logged so workflows can be reviewed.

Secrets management

Credentials and secrets are handled through protected, non-committed mechanisms.

Least privilege

Access is granted at the minimum level needed for a task.

Dependency security

Dependencies are intended to be reviewed and kept current.

Backups & recovery

Data durability and recovery practices are part of the architecture.

Monitoring

Telemetry and alerts are designed to support detection of issues.

Incident response

Detection, containment, investigation, remediation, and notification where required.

Current versus planned, clearly separated.

CapabilityStatusNotes
Tenant isolationDesigned / In platformLogical workspace isolation
TLS in transitDesignedIndustry-standard encryption
Encryption at restPlannedArchitecture designed to support it
Human approval on sendDesigned / In platformFail-closed by default
SOC 2Not claimedSwaylen does not claim certifications it does not hold
ISO 27001Not claimedSwaylen does not claim certifications it does not hold

Swaylen does not claim any security or compliance certification unless it holds verifiable evidence.

Security questions answered directly.

Can another customer see our data?

No. Each customer workspace is logically isolated, and access is authorization-controlled.

Is Swaylen SOC 2 certified?

Not currently claimed. Swaylen does not claim certifications it does not hold.

What happens in an incident?

Swaylen follows detection, containment, investigation, remediation, and customer notification where required.

Can automated outreach be controlled?

Yes. Human approval, suppression, opt-out, rate limits, and feature flags are core design controls.

Security is a design principle, not a checkbox.

Contact Swaylen with any security or compliance questions.