Nothing about your traffic leaves.
Swiftward runs on your own servers and never contacts us: no usage data, no license check. Data leaves only where your configuration sends it, such as events to your SIEM or a prompt to a hosted model, which your policy checks on the way out.
What your team verifies without asking us
| The binary is ours | cosign keyless signature, through the build's OIDC identity |
| What is inside it | SPDX bill of materials, shipped with every image |
| How it was built | SLSA provenance attestation |
| That it is clean | a scan of the image digest for HIGH and CRITICAL vulnerabilities, before the image publishes |
| How it holds up under attack | your penetration test, on your deployment. We support it |
| Where your data went | your own network logs |
Where each control is documented
- Audit and evidence: what the audit trail records, and how a change to it shows up
- Administration: how operators sign in, and how their roles are set
- Authentication and authorization: who may call what
- Secrets and data classification: where credentials are kept
- Data retention: what is kept, and for how long
- Gateways: what happens when Swiftward is unreachable
- Enterprise review questions: the 65 questions an enterprise review asks, with the answers
Regulated data
BAA, data processing agreement, residency terms — we work through whatever your legal team needs. There is little to negotiate, because we never receive your data.
Your system keeps running on its own
You run the binary yourself, on the version you deployed, for as long as you want. Source-code escrow is available where your board asks about continuity.
Your review, your format
During a pilot we complete your questionnaire in CAIQ or SIG and answer whatever it asks.