Frequently asked questions
Trust Center FAQ
Direct, honest answers to the questions hospital security and procurement teams ask most. Where the answer is 'not yet', we say so.
Is SwiftCode HIPAA compliant?
No. SwiftCode is designed with HIPAA Security Rule best practices in mind, but it is not HIPAA compliant or certified, and we do not claim to be. A signed Business Associate Agreement is required before any PHI is exchanged.
Do you have SOC 2, HITRUST, or ISO 27001 certification?
Not currently. We may pursue formal attestation as we mature. In the meantime, we can share our security questionnaire and architecture overview under NDA.
Where is our data stored?
On AWS in the United States (us-west-2), using managed database and cache services.
How is PHI protected?
Through encryption in transit and at rest, role-based access control, per-facility isolation, minimization of PHI in notifications and logs, and durable audit logging.
Do you support single sign-on and multi-factor authentication?
Yes. Sign-in is centralized through SwiftCode ID using OpenID Connect (OAuth 2.0 + PKCE) across web and native apps, with TOTP MFA and passkeys, and enforcement configurable for privileged roles. Enterprise SSO federation to your own identity provider can be discussed during a pilot. MFA never blocks triggering an emergency code.
How are backups handled?
Managed, automated, encrypted database backups with point-in-time recovery. A restore drill is part of our go-live process.
Do you have an uptime SLA?
Not yet. High-availability design is part of production hardening, and we will define availability targets with enterprise customers.
Has SwiftCode had a penetration test?
An independent third-party penetration test is planned before production PHI use. Automated scanning runs continuously today.
How do we request security documentation?
Visit /trust-center/request or email security@swiftcode.tech. Materials can be shared under NDA.
Evaluating SwiftCode for your facility?
Enterprise customers may request our security questionnaire, architecture overview, and pilot materials during procurement — under NDA where required.
Security questions? security@swiftcode.tech