Trust Center

Security and trust at SwiftCode

SwiftCode is a clinical communication and emergency-response platform for behavioral health, psychiatric, skilled nursing, assisted living, and long-term care. This Trust Center explains how we protect clinical data — clearly, and without overstatement.

A note on claims:SwiftCode is designed with HIPAA Security Rule best practices in mind. We are not HIPAA-, SOC 2-, HITRUST-, or ISO 27001-certified, and we do not claim to be. Where a control is still maturing, we say so.

Our security philosophy

Security by design

Security is part of engineering, not a bolt-on. We apply least privilege, per-facility data isolation, and defense in depth across the platform.

Protect the data that matters

TLS protects data in transit and managed at-rest encryption protects it in storage. We minimize the clinical data we place in notifications, logs, and event payloads.

Access by role

Database-backed role-based access control scopes what each staff member can see, enforced from the verified session — never from client input.

Continuous improvement

Automated tests, dependency and secret scanning, and internal reviews run in our pipeline. Controls continue to mature as we progress toward production healthcare deployments.

Explore the Trust Center

Each section describes how a control works at a high level — enough for a security review, without exposing operational detail.

Shared responsibility

Protecting clinical data is a partnership. Here is how responsibility is typically divided in a deployment.

SwiftCode is responsible for

  • Platform, application, and infrastructure security on AWS
  • Encryption in transit and at rest; secrets management
  • Per-facility data isolation and role-based access control
  • Audit logging, monitoring, backups, and incident response
  • Secure development, testing, and vulnerability management

Your facility is responsible for

  • Managing user accounts, roles, and offboarding within your facility
  • Enforcing device management (MDM) and screen-lock on shared devices
  • Protecting staff credentials and second factors
  • Facility policies, workforce training, and clinical workflows
  • Executing a Business Associate Agreement before any PHI is exchanged

Evaluating SwiftCode for your facility?

Enterprise customers may request our security questionnaire, architecture overview, and pilot materials during procurement — under NDA where required.

Security questions? security@swiftcode.tech