Trust & Security

Your governance system should not create another governance problem.

Swell is intended to hold sensitive information about systems, suppliers, controls, incidents and organisational weaknesses. Security, tenant isolation and auditability are therefore product requirements, not later enhancements.

Trust starts with architecture and operating discipline.

The Swell security baseline requires controls appropriate to a multi-tenant governance SaaS. The page deliberately avoids claiming certifications that have not been obtained.

Tenancy

Tenant isolation

Tenant-scoped authorisation should be enforced server-side and in the database, with negative isolation tests rather than relying on UI filtering.

Identity

MFA & least privilege

Customer and support access should use managed authentication, MFA and role-based permissions with separation of duties.

History

Audit logging

Material reads, changes, approvals, exports and support access should leave a customer-visible history.

Data

Encryption & private evidence

TLS, provider-managed encryption at rest and private evidence storage are expected baseline controls.

Resilience

Backups & recovery

Encrypted backups, restore testing and a documented recovery runbook are part of the required operating baseline.

Assurance

Independent testing

Authentication, tenant isolation, authorisation and file access should be independently penetration tested before customer go-live and retested regularly.

Support

Controlled support access

Support access should be time-bound, least-privilege and logged, with no routine copying of customer data into support tickets.

Exit

Export & deletion

Customers should be able to export their data in a usable form and have a documented offboarding and deletion process.

A buyer-assurance choice — not a universal legal claim.

The Swell product requirement is for primary customer database, files and backups to be hosted in Australian regions. We do not claim that Australian law universally requires all AI governance data to remain in Australia; cross-border obligations depend on the data and the circumstances.

Security evidence should be specific.

No claim of ISO 27001 certification until certification exists.
No claim of SOC 2 Type II until an audit has been completed.
No claim that deterministic rules replace legal or security review.
No claim that domestic hosting alone makes a deployment compliant.
No claim that a completed assessment means the organisation is “safe AI”.

Need to discuss a security questionnaire or data-handling requirement?