Security

Security designed around sensitive workforce data.

Attendance records decide pay. Leave records touch health. SWAKIO™ is designed with enterprise security principles, and this page states plainly what is in place, without badge walls or borrowed claims.

Data protection

Data is encrypted in transit and at rest. Workspace sign in rides on your Google Workspace identity, so your 2 step verification and session policies apply.

Identity and access

Role based access with least privilege everywhere. Authentication through your workspace identity provider, with session controls your organisation governs.

Permission boundaries

Employees see their own record. Managers see their team's operations. HR sees what policy allows. Leadership sees aggregates. Tenant isolation separates every organisation.

AI access controls

Agents inherit the asking person's permissions. There is no back door: an agent can only read what that role is authorised to read, and can never execute alone.

Auditability

Who accessed what, what changed, what SWAKIO™ recommended, who approved it and what action occurred. The trail is complete and tamper evident.

Data retention

Retention follows your configuration and your obligations. Full export is available on every plan, and deletion honours your settings and the law that applies to you.

Data minimisation

Security includes what we refuse to collect.

The safest data is the data that never enters the system. SWAKIO™ does not read personal email or files, does not store medical details behind a leave request, and does not build behavioural profiles of individuals. Less honey, fewer bears.

Minimisation is a security control, not just a privacy one.
Talk to us about your security requirements
WHAT AN ATTACKER WOULD NOT FIND
Personal email or file contentsNever collected
Behavioural or emotion profilesNever built
Medical details of leaveNever stored
SWAKIO™ passwordsWorkspace identity instead

Operational practice

Separated environments, reviewed changes, regular backups with restore testing, and production access granted narrowly and reviewed. Infrastructure specifics, including hosting details and subprocessors, are shared with customers on request rather than asserted here.

Incident response

Incidents follow a defined process: contain, assess, notify affected customers without undue delay, remediate and record. Customer administrators are the first to know, not the last.

Vendors and subprocessors

We keep the subprocessor list deliberately short, review vendors before they touch customer data, and make the current list available on request together with the safeguards used for any cross border transfers.

Vulnerability management and disclosure

We patch dependencies routinely and welcome good faith research. If you believe you have found a vulnerability, tell us through the contact page with enough detail to reproduce it. We acknowledge quickly, keep you informed, and do not pursue researchers who respect user data and give us reasonable time to fix.

Responsible AI

AI in SWAKIO™ recommends and never executes alone. Recommendations carry evidence, uncertainty is escalated rather than hidden, no individual is scored, and every AI action and approval lands on the audit record. Our compliance approach is documented on the Compliance page.

Certifications

If a certification or audit report matters to your evaluation, ask us where we are with it. You will get a straight answer with dates, not a wall of badges.

Put your security team in a room with us.