Security & Compliance
We're building SWOT-AI around SOC 2-style controls from the ground up — not bolting them on after the fact. Here's what that means in practice today.
Audit trail
Every admin action, access-control change (like editing a user's admin status), and billing charge is written to a dedicated audit log — recording who did it, to whom, when, and from what IP address. Login and registration events get the same treatment.
These records are append-only: once written, an audit entry can't be edited or deleted through the application, and we're extending that same restriction at the database level so it holds even against direct database access — not just application code.
Encryption
Your account's personal details — name, email, phone, and mailing address — are encrypted at rest using AES-256. Uploaded documents are encrypted the same way. Every connection to SWOT-AI is HTTPS-only.
Access control
Admin actions are restricted to verified admin accounts, re-checked against the database on every request rather than trusted from a cached login session. State-changing requests are protected against cross-site request forgery (CSRF), and every database query is parameterized to prevent injection attacks.
Data retention
Audit and billing records are retained for a defined period to satisfy financial and security accountability needs, then anonymized rather than deleted outright — preserving the historical record for legitimate audit purposes while removing anything that identifies you personally. See our Data Retention Policy for the full policy.
Where we're headed
SOC 2 is a real target for us, not a marketing label — we're building the underlying controls first (audit logging, retention, access control) and pursuing formal certification as the business grows. If you have specific compliance questions for your own due diligence, reach out — we're glad to talk through what's in place today.