Security & compliance.
This page is maintained by SWARMGOOD to answer common security, privacy, and compliance questions from foundations, grantees, and their legal teams. It reflects the controls we have shipped today and the roadmap we have committed to.
SWARMGOOD is a shared-responsibility platform. We are responsible for the security of the platform; foundations and grantees remain responsible for the accuracy of the content they approve and submit. This page is not a certification and does not create a legal warranty.
Where we are today.
Type I readiness assessment complete. Type II observation window opens with our audit partner in early 2026.
Standard DPA with GDPR-aligned SCCs. Redlines supported for foundation legal teams.
Managed cloud infrastructure in US regions. Data residency options available for enterprise tier.
AES-256 at rest, TLS 1.2+ in transit. Secrets managed via a dedicated key manager, not application code.
Foundation admin, program officer, grantee lead, and read-only roles. SAML SSO available for enterprise tier.
All approvals, edits, and data exports are logged with actor, timestamp, and change record for foundation review.
One cohort's data never touches another.
- Each foundation cohort operates in a logically isolated tenant with its own encryption context.
- Grantee data belongs to the grantee. Foundations see only what a grantee explicitly shares, plus aggregated cohort metrics.
- Enterprise tier supports dedicated-tenant deployment for foundations with regulatory constraints.
- No cross-tenant queries, no shared indices between foundation portfolios.
- Grantees own their organizational documents, evidence, and proposals.
- Full export in structured formats (JSON, CSV, PDF) at any time. No lock-in.
- Deletion within 30 days of request; audit-log retention follows the DPA schedule.
- If a foundation and grantee part ways, the grantee keeps their workspace.
Our position on model training.
Grantee content, foundation documents, evidence, and approved narratives are never used to train third-party foundation models. Provider APIs are configured with zero data retention where the provider supports it, and with contractual no-training clauses where they do.
- No model training on customer data — grantee or foundation.
- No selling of customer data. Ever.
- No PII in training corpora or retrieval indices used across tenants.
- Aggregate, anonymized workflow metrics may inform our own internal templates — always opt-in at the cohort level.
- Human approval gate on every generated output before it can leave the platform.
- Prompts, retrieved context, and outputs are logged for the customer's own audit only.
What paperwork you can expect.
Standard MSA aligned to foundation procurement norms. Redlines supported.
GDPR-aligned DPA with SCCs. Subprocessor list published on request.
CAIQ-lite and SIG-lite responses available. Foundation-specific questionnaires supported.
Commercial general liability, professional liability, and cyber insurance. Certificates on request.
How we respond when something goes wrong.
24/7 alerting on platform anomalies, auth failures, and unusual data-access patterns.
Foundation admins notified within 72 hours of confirmed incident affecting their tenant, per DPA terms.
Written incident report shared with affected foundations within 14 days, including root cause and remediation.
To report a security concern or coordinate responsible disclosure, contact security@swarmgood.com.
Need to run this by your team?
Request our DPA, security questionnaire, and subprocessor list. We'll route it to your foundation's legal contact within one business day.