Trust Center
Security and trust at SwiftCode
SwiftCode is a clinical communication and emergency-response platform for behavioral health, psychiatric, skilled nursing, assisted living, and long-term care. This Trust Center explains how we protect clinical data — clearly, and without overstatement.
A note on claims:SwiftCode is designed with HIPAA Security Rule best practices in mind. We are not HIPAA-, SOC 2-, HITRUST-, or ISO 27001-certified, and we do not claim to be. Where a control is still maturing, we say so.
Our security philosophy
Security by design
Security is part of engineering, not a bolt-on. We apply least privilege, per-facility data isolation, and defense in depth across the platform.
Protect the data that matters
TLS protects data in transit and managed at-rest encryption protects it in storage. We minimize the clinical data we place in notifications, logs, and event payloads.
Access by role
Database-backed role-based access control scopes what each staff member can see, enforced from the verified session — never from client input.
Continuous improvement
Automated tests, dependency and secret scanning, and internal reviews run in our pipeline. Controls continue to mature as we progress toward production healthcare deployments.
Explore the Trust Center
Each section describes how a control works at a high level — enough for a security review, without exposing operational detail.
Security overview
Security-first engineering, defense in depth, least privilege, and continuous review.
Platform architecture
A clinical layer built on trusted platforms — ZITADEL for identity, AWS for cloud, Matrix Synapse planned for messaging.
Infrastructure
AWS hosting in the United States, private networking, encryption, and managed data services.
Data protection
Encryption in transit and at rest, secrets management, data minimization, and audit logging.
Authentication & access
Role-based access control, multi-factor authentication, and server-side session revocation.
Secure development
Code review, CI/CD gates, automated testing, dependency and secret scanning.
Incident response
Preparation, detection, containment, recovery, communication, and learning.
Business continuity
High-availability design, backups, disaster recovery, and operational resilience.
Healthcare readiness
An honest view of maturity, HIPAA Security Rule alignment, and our pilot approach.
Privacy
Minimum-necessary access, patient confidentiality, and administrative safeguards.
Responsible disclosure
How to report a vulnerability, our response process, scope, and safe harbor.
FAQ
Direct answers to the questions hospital security and procurement teams ask most.
Request documentation
Request our security questionnaire, architecture overview, and pilot materials — under NDA if needed.
Shared responsibility
Protecting clinical data is a partnership. Here is how responsibility is typically divided in a deployment.
SwiftCode is responsible for
- Platform, application, and infrastructure security on AWS
- Encryption in transit and at rest; secrets management
- Per-facility data isolation and role-based access control
- Audit logging, monitoring, backups, and incident response
- Secure development, testing, and vulnerability management
Your facility is responsible for
- Managing user accounts, roles, and offboarding within your facility
- Enforcing device management (MDM) and screen-lock on shared devices
- Protecting staff credentials and second factors
- Facility policies, workforce training, and clinical workflows
- Executing a Business Associate Agreement before any PHI is exchanged
Evaluating SwiftCode for your facility?
Enterprise customers may request our security questionnaire, architecture overview, and pilot materials during procurement — under NDA where required.
Security questions? security@swiftcode.tech