Trust Center

Security and trust at SwiftCode

SwiftCode is a clinical communication and emergency-response platform for behavioral health, psychiatric, skilled nursing, assisted living, and long-term care. This Trust Center explains how we protect clinical data — clearly, and without overstatement.

A note on claims:SwiftCode is designed with HIPAA Security Rule best practices in mind. We are not HIPAA-, SOC 2-, HITRUST-, or ISO 27001-certified, and we do not claim to be. Where a control is still maturing, we say so.

Our security philosophy

Security by design

Security is part of engineering, not a bolt-on. We apply least privilege, per-facility data isolation, and defense in depth across the platform.

Protect the data that matters

TLS protects data in transit and managed at-rest encryption protects it in storage. We minimize the clinical data we place in notifications, logs, and event payloads.

Access by role

Database-backed role-based access control scopes what each staff member can see, enforced from the verified session — never from client input.

Continuous improvement

Automated tests, dependency and secret scanning, and internal reviews run in our pipeline. Controls continue to mature as we progress toward production healthcare deployments.

Explore the Trust Center

Each section describes how a control works at a high level — enough for a security review, without exposing operational detail.

Security overview

Security-first engineering, defense in depth, least privilege, and continuous review.

Platform architecture

A clinical platform built on trusted foundations: ZITADEL for identity today (WorkOS planned), AWS for cloud, and SwiftCode's own in-house secure clinical messaging.

Reliability

Durable-first alerting: the database is the source of truth, delivery transports are asynchronous carriers, and human acknowledgement is an explicit, auditable fact.

Infrastructure

AWS hosting in the United States, private networking, encryption, and managed data services.

Data protection

Encryption in transit and at rest, secrets management, data minimization, and audit logging.

Authentication & access

Role-based access control, multi-factor authentication, and server-side session revocation.

Secure development

Code review, CI/CD gates, automated testing, dependency and secret scanning.

Incident response

Preparation, detection, containment, recovery, communication, and learning.

Business continuity

High-availability design, backups, disaster recovery, and operational resilience.

Healthcare readiness

An honest view of maturity, HIPAA Security Rule alignment, and our pilot approach.

Privacy

Minimum-necessary access, patient confidentiality, and administrative safeguards.

Responsible disclosure

How to report a vulnerability, our response process, scope, and safe harbor.

FAQ

Direct answers to the questions hospital security and procurement teams ask most.

Request documentation

Request our security questionnaire, architecture overview, and pilot materials — under NDA if needed.

Shared responsibility

Protecting clinical data is a partnership. Here is how responsibility is typically divided in a deployment.

SwiftCode is responsible for

  • Platform, application, and infrastructure security on AWS
  • Encryption in transit and at rest; secrets management
  • Per-facility data isolation and role-based access control
  • Audit logging, monitoring, backups, and incident response
  • Secure development, testing, and vulnerability management

Your facility is responsible for

  • Managing user accounts, roles, and offboarding within your facility
  • Enforcing device management (MDM) and screen-lock on shared devices
  • Protecting staff credentials and second factors
  • Facility policies, workforce training, and clinical workflows
  • Executing a Business Associate Agreement before any PHI is exchanged

Evaluating SwiftCode for your facility?

Enterprise customers may request our security questionnaire, architecture overview, and pilot materials during procurement — under NDA where required.

Security questions? security@swiftcode.tech