Security at Swish

Swish handles shopper data for the merchants who install our app. Here is how we keep it safe.

Visit our Trust Center

Governance

Security policies

Our security program is set out in written policies, from access control and cryptography to secure development and incident response. Each one is formally approved and reviewed every year.

Least privilege

Access to production is granted on the principle of least privilege.

Defence in depth

We build in layers. The Swish API sits behind Google Cloud Armor and accepts traffic only through Google’s load balancer, and our background services cannot be reached from the internet.

Compliance

Trust Center

We monitor our security controls continuously with Vanta. Our Trust Center shows those controls as they are monitored, and our current list of sub-processors.

Data protection

The Swish platform runs on Google Cloud and MongoDB Atlas in the European Union and the United States. We operate no data centres of our own, and physical security is the responsibility of those providers.

Data at rest

Data at rest is encrypted by default by Google Cloud and MongoDB Atlas.

Data in transit

Traffic to Swish is encrypted over HTTPS, plain HTTP is redirected to HTTPS, and our load balancers enforce TLS 1.2 as the minimum protocol version.

Secrets

Application secrets are held in Google Secret Manager. Store integration credentials in our Spanner database are additionally encrypted with Google Cloud KMS.

Product security

Vulnerability management

We run a vulnerability management process, with findings tracked against remediation deadlines set by severity.

Enterprise security

Access control

Privileged access to production requires multi-factor authentication, and access is removed when someone leaves Swish.

Security training

Everyone at Swish completes security awareness training.

Data privacy

For shopper personal data, Swish acts as a processor on behalf of the merchant, who is the controller.

Data Processing Agreement

Our Data Processing Agreement applies to every merchant and sets out how we process shopper data, including deletion when a store uninstalls Swish.

Privacy Policy

Our Privacy Policy sets out what we collect, why, and how to exercise your rights over it.

Sub-processors

The providers that process shopper data for us are listed in Annex 3 of our Data Processing Agreement, with a dated record of changes. Our Trust Center shows the current list.

Incident response

Breach notification

We follow a documented incident response plan. If a personal data breach affects a merchant’s data, we notify that merchant without undue delay, and in any event within 48 hours of becoming aware of it.

Reporting a vulnerability

How to report

If you believe you have found a security vulnerability in Swish, please report it to security@swish.app with enough detail for us to reproduce the issue.

Responsible disclosure

Please give us a reasonable opportunity to investigate and resolve an issue before disclosing it publicly, and do not access, modify or delete data belonging to anyone else while testing.