Trust & Security

Your customers' calls are your business. We treat them that way.

Swiftlee answers the phone for small businesses across regulated and everyday industries alike. Here's exactly how we protect the calls, messages, and customer information that pass through the platform — no hand-waving, just the controls we actually run.

Encryption everywhere

All traffic is served over TLS with HSTS (2-year max-age, preload-eligible) and automatic HTTPS upgrades. Data is encrypted at rest in our database and in call-recording storage.

Tenant isolation

Every business's data is fenced by row-level security in Postgres, and server-side access is scoped to your own company on every read and write. One customer can never see another's calls, messages, or contacts.

Access control & 2FA

Role-based access separates owners, agents, and managers, each seeing only what they need. Optional two-factor authentication (authenticator app) is available on every account from Account → Security.

Payments never touch our servers

Billing runs entirely through Stripe (PCI DSS Level 1). Swiftlee never sees, stores, or transmits your full card number — Stripe handles card data end-to-end.

HIPAA mode & BAAs

Healthcare-adjacent customers can enable HIPAA mode: minimum-necessary intake, PHI kept out of logs and SMS, and features that lack a BAA disabled. We sign a Business Associate Agreement before any PHI flows through the platform.

Monitoring & audit trails

Errors are tracked with personal data stripped from reports, and sensitive administrative actions are written to an audit log. Webhook deliveries to your systems are signed and logged.

Signed integrations

Every inbound webhook from our telephony, payment, and email providers is cryptographically verified and replay-protected before we act on it. Our own webhooks to you are signed the same way so you can verify they're really from Swiftlee.

US data residency & portability

Your data is hosted in the United States. It's yours to take with you: export calls and contacts to CSV any time, and request deletion from your account settings.

Compliance posture

Swiftlee runs on infrastructure that is independently SOC 2 Type II and ISO 27001 certified — Supabase, Vercel, AWS, Stripe, and Cloudflare — and we build to SOC 2-aligned controls across access, encryption, change management, and monitoring. A formal SOC 2 examination of Swiftlee itself is on our roadmap; if your procurement process needs our current control documentation in the meantime, reach out and we'll share what we have.

For healthcare and healthcare-adjacent customers, Swiftlee offers HIPAA mode and signs a Business Associate Agreement before any protected health information is transmitted through the platform.

Subprocessors

We rely on a small set of established, independently audited providers to run the service. Each processes only the data needed for its role:

SupabaseApplication database & authentication
VercelApplication hosting
TelnyxTelephony & SMS
Vapi / OpenAIAI voice & language processing
StripePayment processing (PCI DSS Level 1)
ResendTransactional email
Cloudflare R2Call-recording storage

Report a vulnerability

Found a security issue? Email security@getswiftlee.com with the details and steps to reproduce. We investigate every good-faith report, won't pursue action against researchers who act responsibly, and will keep you updated as we fix it.

Related: Privacy Policy · Data Processing Agreement · Service Level Agreement · System status

Last reviewed July 2026.

Start freeCall