Security
Your data belongs to you. We keep it that way.
Swepety is built with security as a foundation, not an afterthought. Every layer of the stack is designed to protect your leads, conversations, and workspace.
Encryption at Rest & In Transit
All data is encrypted using AES-256 at rest and TLS 1.3 in transit. Your lead information, conversations, and workspace data are protected at every layer of the stack.
Row-Level Isolation
Every team operates in an isolated workspace with strict row-level security. Your data is invisible to other workspaces — no shared tables, no cross-tenant access.
Signature-Verified Webhooks
Every incoming lead webhook is cryptographically signed. We verify each request before processing, preventing spoofed or tampered lead submissions.
SOC 2 Infrastructure
We run on AWS with SOC 2 compliant data centers. Physical security, network monitoring, and access controls meet enterprise-grade standards.
Team Access Controls
Role-based permissions let you control who can view, manage, or export leads and conversations. Audit logs track every action in your workspace.
GDPR & CCPA Compliant
We adhere to GDPR and CCPA requirements. You can export or delete your data at any time. We never sell personal information or train models on your leads.
Responsible Disclosure
If you discover a security vulnerability in Swepety, we encourage you to report it responsibly. Send details to security@swepety.com. We commit to acknowledging your report within 24 hours and working toward a resolution before public disclosure.