Account access
Swep supports passwordless email-code authentication and Google sign-in. Authentication state is handled through the application’s managed identity layer rather than custom password storage.
Workspace and project permissions distinguish owners, editors, and viewers. Product actions are checked against the authenticated user and the access available to that account.
Workspace and sharing controls
Project data is scoped to its workspace. Public reports use separate share links, while project API access uses dedicated credentials that can be managed independently from a user session.
Teams should treat exported reports, public links, and API keys as sensitive and revoke or rotate access when it is no longer needed.
Payments and service providers
Subscription checkout and payment details are handled by Stripe. Swep receives the billing and subscription information needed to activate and manage a plan; payment-card entry occurs on Stripe’s hosted flow.
Swep uses specialized infrastructure and AI providers to operate analysis workflows. The privacy policy explains the categories of information used to provide the service.
Responsible product behavior
The product distinguishes observed results, estimates, pending analysis, and unavailable data so an absent measurement is not represented as a successful or failed security-relevant fact.
Generated recommendations are working material, not an authorization to publish unsupported claims. Teams remain responsible for reviewing evidence, permissions, and customer-facing statements before deployment.
Current scope
Swep does not currently claim SOC 2, ISO 27001, HIPAA, or another independent certification on this page. Organizations with procurement, data-residency, retention, or contractual requirements should contact us before purchase so we can confirm what is available today.