Security
Your data belongs to you. We keep it that way.
Swepety is built with security as a foundation, not an afterthought. Every layer of the stack is designed to protect your orders, documents, and workspace.
Encryption at Rest & In Transit
All data is encrypted using AES-256 at rest and TLS 1.3 in transit. Your order data, source documents, and workspace data are protected at every layer of the stack.
Row-Level Isolation
Every team operates in an isolated workspace with strict row-level security. Your data is invisible to other workspaces — no shared tables, no cross-tenant access.
Signature-Verified Webhooks
Every incoming intake request is cryptographically signed. We verify each request before processing, preventing spoofed or tampered order submissions.
SOC 2 Infrastructure
We run on AWS with SOC 2 compliant data centers. Physical security, network monitoring, and access controls meet enterprise-grade standards.
Team Access Controls
Role-based permissions let you control who can view, manage, or export orders and documents. Audit logs track every action in your workspace.
GDPR & CCPA Compliant
We adhere to GDPR and CCPA requirements. You can export or delete your data at any time. We never sell personal information or train models on your order data.
Responsible Disclosure
If you discover a security vulnerability in Swepety, we encourage you to report it responsibly. Send details to security@swepety.com. We commit to acknowledging your report within 24 hours and working toward a resolution before public disclosure.