← Trust Center

Platform architecture

Platform architecture

SwiftCode is a clinical layer built on top of mature, enterprise-grade platforms. We focus our engineering on hospitals, staff, roles, and emergency workflows — and delegate security-critical infrastructure like identity and cloud hosting to established providers, rather than reinventing it.

Separation of responsibilities

SwiftCode is built as layers with clear ownership: identity is delegated to ZITADEL Cloud, while SwiftCode owns authorization and the clinical business logic. Together they deliver the healthcare communication platform.

Identity LayerDelegated to ZITADEL Cloud

Authentication · Single Sign-On · Multi-Factor Authentication · Passkeys · Identity Federation

Application LayerOwned by SwiftCode

Authorization · Hospitals · Facilities · Staff · Roles & Permissions · Clinical Workflows

Healthcare Communication Platform

Incidents · Alerts · Messaging · Operations

Delegated to ZITADEL Owned by SwiftCode Capabilities
SwiftCode is built on a layered architecture that separates identity management from healthcare business logic. Authentication is delegated to ZITADEL Cloud, while SwiftCode remains the authoritative source for authorization, clinical workflows, and healthcare operations. This separation improves security, simplifies compliance, and allows us to leverage trusted enterprise technologies without compromising control over patient care workflows.

How it connects to trusted platforms

The same architecture from an infrastructure view: clinical staff use SwiftCode across four surfaces, while identity, cloud, and (planned) messaging are handled by dedicated platforms.

  • SwiftCodeHospitals, staff, roles, permissions, authorization, clinical workflows, and emergency communication.
  • ZITADEL CloudIdentity and authentication — SSO, MFA, passkeys, OIDC / OAuth 2.0.
  • Matrix SynapseSecure messaging transport, sync, presence, attachments, and end-to-end-encryption capability. Planned.
  • Amazon Web ServicesCloud foundation — availability, encryption, backups, and disaster recovery.
SwiftCode (built in-house) Delegated platform Planned Cloud foundation

Built on trusted technologies

SwiftCode intentionally builds on mature, enterprise-grade platforms instead of recreating security-sensitive infrastructure. This keeps critical controls in the hands of specialists whose entire business is getting them right.

Identity

Authentication is delegated to ZITADEL Cloud.

ZITADEL provides

  • Single sign-on (SSO)
  • Multi-factor authentication (MFA)
  • Passkeys / WebAuthn
  • OpenID Connect (OIDC) and OAuth 2.0
  • Enterprise identity federation

SwiftCode owns

SwiftCode resolves roles, permissions, and facility scope itself — so identity and authorization stay cleanly separated.

Messaging

Secure messaging is planned to be delegated to Matrix Synapse.

Planned

Matrix provides

  • Secure message transport
  • Synchronization across devices
  • Presence
  • Attachments
  • End-to-end encryption capabilities

SwiftCode owns

SwiftCode remains responsible for hospitals, staff, roles, permissions, authorization, clinical workflows, and emergency communication.

Cloud infrastructure

SwiftCode is deployed on Amazon Web Services.

AWS provides

  • High availability
  • Scalability
  • Encryption
  • Automated backups
  • Disaster recovery
  • Continuous monitoring

SwiftCode owns

Infrastructure is defined as code and continuously monitored, so environments are reproducible and changes are reviewable.

SwiftCode ID credentials are held by ZITADEL Cloud, not SwiftCode. Passwords, MFA, and passkeys for SwiftCode ID are held and verified by ZITADEL; SwiftCode receives a standards-based identity token — never those credentials — and resolves what each user may do from their SwiftCode role. We are retiring the legacy password sign-in path as staff move to SwiftCode ID.

Compliance at the identity layer

Because authentication is delegated to ZITADEL Cloud, the identity layer runs on a service that ZITADEL independently certifies and operates as a data processor — so credentials, MFA, and passkeys sit behind an audited, standards-based platform.

ZITADEL Cloud certifications

Maintained and attested by ZITADEL for the identity service.

ISO 27001 CertifiedSOC 2 Type IIGDPR (Data Processor)HIPAAOpenID CertifiedEU-U.S. / UK / Swiss Data Privacy Framework

Data residency

Identity data can be pinned to Switzerland, the European Union, or Global regions.

Data processing

A Data Processing Agreement is available with standard contractual clauses, technical & organizational measures, and a published sub-processor list.

What this does — and doesn't — mean. The certifications above are ZITADEL Cloud's own, covering the identity service SwiftCode relies on; they are verifiable at zitadel.com/gdpr. They strengthen the identity layer, but they do notcertify SwiftCode itself. SwiftCode is not HIPAA-, SOC 2-, or ISO 27001-certified, and does not claim to be.

Designed for healthcare

A clear, honest view of what "HIPAA" means for software — and how SwiftCode is built with the HIPAA Security Rule in mind.

There is no official HIPAA certification for software. HIPAA compliance depends on how systems are designed, deployed, configured, and operated — it is a property of an organization and its environment, not a badge a product can earn. SwiftCode is built with healthcare security principles in mind by leveraging trusted technologies and operational best practices; we do not claim to be HIPAA-certified, and we make no legal guarantees.

The security measures our design centers on include:

  • Encryption in transit (TLS)
  • Encryption at rest
  • Centralized identity management
  • Audit logging of security-relevant actions
  • Least-privilege, role-based access control
  • Continuous monitoring
  • Disaster recovery and backup strategies
  • Infrastructure as code

Compliance is a shared, organizational effort

Even with strong technical controls, HIPAA compliance also requires work that lives with the healthcare organization and its operating environment:

  • Organizational policies
  • Administrative safeguards
  • Workforce training
  • Risk assessments
  • Business Associate Agreements (BAAs), where applicable

For an honest view of our current maturity and HIPAA Security Rule alignment, see Healthcare readiness.

Security principles

The commitments behind the architecture, at a glance.

Authentication managed by ZITADEL
Secure messaging powered by Matrix Synapse (planned)
Hosted on Amazon Web Services
Encryption by default
Least-privilege architecture
Security-first engineering

Evaluating SwiftCode for your facility?

Enterprise customers may request our security questionnaire, architecture overview, and pilot materials during procurement — under NDA where required.

Security questions? security@swiftcode.tech