← Trust Center

Privacy

Privacy

SwiftCode is built to handle sensitive clinical information carefully. This is a summary of how we approach privacy across the platform — for the full, binding terms, see our privacy policy.

Privacy principles

We start from restraint: collect and expose only what the workflow needs.

  • Collect and expose the minimum necessary information to operate the service.
  • Clinical data is used to run the platform for the facility — it is never sold.
  • Sensitive detail is kept out of notifications, logs, and event payloads wherever possible.
  • Data access is scoped to the facility and role that legitimately needs it.

Minimum necessary access

Role-based access control and per-facility isolation limit who can see what.

  • Database-backed role-based access control with granular, per-role permissions.
  • Per-facility data isolation enforced at the API layer on every read and write.
  • A facility sees only its own incidents, staff, and patients — never another facility's.
  • Administrative access is restricted and recorded.

Patient confidentiality

We minimize protected health information in the places it is most likely to leak.

  • PHI is minimized in notifications, logs, and durable event payloads.
  • Lock-screen notifications are generic and avoid revealing patient detail.
  • Only the detail required for a responder to act is surfaced in alerts.
  • Clinical detail stays within authenticated, authorized surfaces of the app.

Administrative safeguards

People and process controls back up the technical ones.

  • Access reviews to confirm permissions still match each person's role.
  • Least-privilege defaults for staff, administrators, and services.
  • Durable, append-only audit logging of critical security and clinical events.
  • Deactivation and role changes revoke access promptly.

Technical safeguards

Encryption, authentication, and revocation protect data in motion and at rest.

  • Encryption in transit and at rest.
  • Authenticated sessions with signed, short-lived tokens.
  • Server-side session revocation on logout, deactivation, or role change.
  • Realtime connections authenticated and authorized per facility.

Organizational safeguards

Contracts and vendor management extend our privacy commitments beyond our own systems.

  • Business Associate Agreements with customers before any PHI is exchanged.
  • Subprocessor management to track and limit third parties that touch data.
  • Data handling scoped to what is needed to deliver and support the service.
This page is a summary, not a legal policy. For the complete terms that govern how we handle data, see our full privacy policy.

Evaluating SwiftCode for your facility?

Enterprise customers may request our security questionnaire, architecture overview, and pilot materials during procurement — under NDA where required.

Security questions? security@swiftcode.tech