User Guide › Security & Compliance

Security & Compliance

We're building SWOT-AI around SOC 2-style controls from the ground up — not bolting them on after the fact. Here's what that means in practice today.

Audit trail

Every admin action, access-control change (like editing a user's admin status), and billing charge is written to a dedicated audit log — recording who did it, to whom, when, and from what IP address. Login and registration events get the same treatment.

These records are append-only: once written, an audit entry can't be edited or deleted through the application, and we're extending that same restriction at the database level so it holds even against direct database access — not just application code.

Encryption

Your account's personal details — name, email, phone, and mailing address — are encrypted at rest using AES-256. Uploaded documents are encrypted the same way. Every connection to SWOT-AI is HTTPS-only.

Access control

Admin actions are restricted to verified admin accounts, re-checked against the database on every request rather than trusted from a cached login session. State-changing requests are protected against cross-site request forgery (CSRF), and every database query is parameterized to prevent injection attacks.

Data retention

Audit and billing records are retained for a defined period to satisfy financial and security accountability needs, then anonymized rather than deleted outright — preserving the historical record for legitimate audit purposes while removing anything that identifies you personally. See our Data Retention Policy for the full policy.

Where we're headed

SOC 2 is a real target for us, not a marketing label — we're building the underlying controls first (audit logging, retention, access control) and pursuing formal certification as the business grows. If you have specific compliance questions for your own due diligence, reach out — we're glad to talk through what's in place today.