Platform architecture
Platform architecture
SwiftCode is a clinical layer built on top of mature, enterprise-grade platforms. We focus our engineering on hospitals, staff, roles, and emergency workflows — and delegate security-critical infrastructure like identity and cloud hosting to established providers, rather than reinventing it.
Separation of responsibilities
SwiftCode is built as layers with clear ownership: SwiftCode ID sign-in is delegated to ZITADEL Cloud, while SwiftCode owns authorization and the clinical business logic. Together they deliver the healthcare communication platform.
Authentication · Single Sign-On · Multi-Factor Authentication · Passkeys · Identity Federation
Authorization · Hospitals · Facilities · Staff · Roles & Permissions · Clinical Workflows
Incidents · Alerts · Messaging · Operations
SwiftCode is built on a layered architecture that separates identity management from healthcare business logic. SwiftCode ID authentication is delegated to ZITADEL Cloud, while SwiftCode remains the authoritative source for authorization, clinical workflows, and healthcare operations. This separation improves security, simplifies compliance, and allows us to leverage trusted enterprise technologies without compromising control over patient care workflows.
How it connects to trusted platforms
The same architecture from an infrastructure view: clinical staff use SwiftCode across four surfaces, while identity, cloud, and (planned) messaging are handled by dedicated platforms.
- SwiftCode Platform — Hospitals, facilities, staff, roles, permissions, authorization, clinical workflows, and emergency codes.
- Clinical Communication (in-house) — Incidents, alerts, secure messaging, clinical notes, QR verification, and the audit trail — built and owned by SwiftCode, with AES field-level message encryption.
- Identity Platform — Authentication, MFA, passkeys, enterprise SSO, and federation. ZITADEL Cloud today; WorkOS is the planned future direction.
- Amazon Web Services — Cloud foundation — availability, encryption, backups, and disaster recovery.
Built on trusted technologies
SwiftCode intentionally builds on mature, enterprise-grade platforms instead of recreating security-sensitive infrastructure. This keeps critical controls in the hands of specialists whose entire business is getting them right.
Identity
SwiftCode ID sign-in is delegated to ZITADEL Cloud today, and the legacy password path is being retired as staff migrate. WorkOS is the planned future identity platform; the migration path is documented and ZITADEL remains in production until then.
ZITADEL provides
- Single sign-on (SSO)
- Multi-factor authentication (MFA)
- Passkeys / WebAuthn
- OpenID Connect (OIDC) and OAuth 2.0
- Enterprise identity federation
SwiftCode owns
SwiftCode resolves roles, permissions, and facility scope itself — so identity and authorization stay cleanly separated regardless of the identity provider.
Messaging
Secure clinical messaging is built and owned in-house by SwiftCode — because it is PHI-aware, integrates with incidents and clinical notes, and must be encrypted and audited.
SwiftCode provides
- PHI-aware secure messaging
- AES field-level message encryption
- Audit logging + retention/disposal
- Incident & clinical-note integration
- Delivery/read receipts and presence (roadmap)
SwiftCode owns
SwiftCode owns the full messaging path: PHI minimization, AES field-level encryption of message bodies, retention/disposal, and audit logging — tied directly into incident and clinical workflows.
Cloud infrastructure
SwiftCode is deployed on Amazon Web Services.
AWS provides
- High availability
- Scalability
- Encryption
- Automated backups
- Disaster recovery
- Continuous monitoring
SwiftCode owns
Infrastructure is defined as code and continuously monitored, so environments are reproducible and changes are reviewable.
Compliance at the identity layer
Because SwiftCode ID sign-in is delegated to ZITADEL Cloud, the identity layer runs on a service that ZITADEL independently certifies and operates as a data processor — so credentials, MFA, and passkeys sit behind an audited, standards-based platform.
ZITADEL Cloud certifications
Maintained and attested by ZITADEL for the identity service.
Data residency
Identity data can be pinned to Switzerland, the European Union, or Global regions.
Data processing
A Data Processing Agreement is available with standard contractual clauses, technical & organizational measures, and a published sub-processor list.
Designed for healthcare
A clear, honest view of what "HIPAA" means for software — and how SwiftCode is built with the HIPAA Security Rule in mind.
The security measures our design centers on include the following. Field-level encryption of message bodies and clinical notes is live today; some infrastructure controls (network TLS termination and database-level encryption at rest) are defined in our infrastructure-as-code and pending final production cutover — see Healthcare readiness for live status.
- Field-level encryption of message bodies and clinical notes (AES-256-GCM)
- Encryption in transit (TLS) and database-level encryption at rest
- Centralized identity management
- Audit logging of security-relevant actions
- Least-privilege, role-based access control
- Continuous monitoring
- Disaster recovery and backup strategies
- Infrastructure as code
Compliance is a shared, organizational effort
Even with strong technical controls, HIPAA compliance also requires work that lives with the healthcare organization and its operating environment:
- Organizational policies
- Administrative safeguards
- Workforce training
- Risk assessments
- Business Associate Agreements (BAAs), where applicable
For an honest view of our current maturity and HIPAA Security Rule alignment, see Healthcare readiness.
Security principles
The commitments behind the architecture, at a glance.
Evaluating SwiftCode for your facility?
Enterprise customers may request our security questionnaire, architecture overview, and pilot materials during procurement — under NDA where required.
Security questions? security@swiftcode.tech