Security
Security by design, stated honestly.
Swaylen is designed with secure defaults, controlled automation, and clear boundaries. Where a capability is planned rather than live, we say so.
Security pillars
What Swaylen is designed to support.
Tenant isolation
Each customer workspace is logically isolated from other customers.
Authentication & authorization
Access is controlled and role-aware, with least-privilege behavior.
Encryption in transit
Traffic is encrypted in transit using industry-standard TLS.
Secure defaults
The product is designed to be safe by default, requiring explicit action to widen access.
Fail-closed controls
Automation does not act without explicit approval; permissions fail closed.
Auditability
Actions and changes are logged so workflows can be reviewed.
Secrets management
Credentials and secrets are handled through protected, non-committed mechanisms.
Least privilege
Access is granted at the minimum level needed for a task.
Dependency security
Dependencies are intended to be reviewed and kept current.
Backups & recovery
Data durability and recovery practices are part of the architecture.
Monitoring
Telemetry and alerts are designed to support detection of issues.
Incident response
Detection, containment, investigation, remediation, and notification where required.
Status labeling
Current versus planned, clearly separated.
| Capability | Status | Notes |
|---|---|---|
| Tenant isolation | Designed / In platform | Logical workspace isolation |
| TLS in transit | Designed | Industry-standard encryption |
| Encryption at rest | Planned | Architecture designed to support it |
| Human approval on send | Designed / In platform | Fail-closed by default |
| SOC 2 | Not claimed | Swaylen does not claim certifications it does not hold |
| ISO 27001 | Not claimed | Swaylen does not claim certifications it does not hold |
Swaylen does not claim any security or compliance certification unless it holds verifiable evidence.
Holding us accountable
Security questions answered directly.
Can another customer see our data?
No. Each customer workspace is logically isolated, and access is authorization-controlled.
Is Swaylen SOC 2 certified?
Not currently claimed. Swaylen does not claim certifications it does not hold.
What happens in an incident?
Swaylen follows detection, containment, investigation, remediation, and customer notification where required.
Can automated outreach be controlled?
Yes. Human approval, suppression, opt-out, rate limits, and feature flags are core design controls.
Security is a design principle, not a checkbox.
Contact Swaylen with any security or compliance questions.