Skip to content
Trust · maintained by SWARMGOOD

Security & compliance.

This page is maintained by SWARMGOOD to answer common security, privacy, and compliance questions from foundations, grantees, and their legal teams. It reflects the controls we have shipped today and the roadmap we have committed to.

SWARMGOOD is a shared-responsibility platform. We are responsible for the security of the platform; foundations and grantees remain responsible for the accuracy of the content they approve and submit. This page is not a certification and does not create a legal warranty.

Program status

Where we are today.

SOC 2 Type II
In progress · target 2026 Q2

Type I readiness assessment complete. Type II observation window opens with our audit partner in early 2026.

Data Processing Agreement (DPA)
Available on request

Standard DPA with GDPR-aligned SCCs. Redlines supported for foundation legal teams.

Hosting
US-region cloud

Managed cloud infrastructure in US regions. Data residency options available for enterprise tier.

Encryption
At rest & in transit

AES-256 at rest, TLS 1.2+ in transit. Secrets managed via a dedicated key manager, not application code.

Access control
Role-based, SSO-ready

Foundation admin, program officer, grantee lead, and read-only roles. SAML SSO available for enterprise tier.

Audit logging
Enabled by default

All approvals, edits, and data exports are logged with actor, timestamp, and change record for foundation review.

Data isolation

One cohort's data never touches another.

Tenant model
  • Each foundation cohort operates in a logically isolated tenant with its own encryption context.
  • Grantee data belongs to the grantee. Foundations see only what a grantee explicitly shares, plus aggregated cohort metrics.
  • Enterprise tier supports dedicated-tenant deployment for foundations with regulatory constraints.
  • No cross-tenant queries, no shared indices between foundation portfolios.
Grantee data ownership
  • Grantees own their organizational documents, evidence, and proposals.
  • Full export in structured formats (JSON, CSV, PDF) at any time. No lock-in.
  • Deletion within 30 days of request; audit-log retention follows the DPA schedule.
  • If a foundation and grantee part ways, the grantee keeps their workspace.
AI & privacy

Our position on model training.

Model training policy
Customer data is not used to train foundation models.

Grantee content, foundation documents, evidence, and approved narratives are never used to train third-party foundation models. Provider APIs are configured with zero data retention where the provider supports it, and with contractual no-training clauses where they do.

  • No model training on customer data — grantee or foundation.
  • No selling of customer data. Ever.
  • No PII in training corpora or retrieval indices used across tenants.
  • Aggregate, anonymized workflow metrics may inform our own internal templates — always opt-in at the cohort level.
  • Human approval gate on every generated output before it can leave the platform.
  • Prompts, retrieved context, and outputs are logged for the customer's own audit only.
Legal & contracting

What paperwork you can expect.

Master Services Agreement

Standard MSA aligned to foundation procurement norms. Redlines supported.

Data Processing Agreement

GDPR-aligned DPA with SCCs. Subprocessor list published on request.

Security questionnaires

CAIQ-lite and SIG-lite responses available. Foundation-specific questionnaires supported.

Insurance

Commercial general liability, professional liability, and cyber insurance. Certificates on request.

Incident response

How we respond when something goes wrong.

DETECTION

24/7 alerting on platform anomalies, auth failures, and unusual data-access patterns.

NOTIFICATION

Foundation admins notified within 72 hours of confirmed incident affecting their tenant, per DPA terms.

POST-MORTEM

Written incident report shared with affected foundations within 14 days, including root cause and remediation.

To report a security concern or coordinate responsible disclosure, contact security@swarmgood.com.

For legal & procurement

Need to run this by your team?

Request our DPA, security questionnaire, and subprocessor list. We'll route it to your foundation's legal contact within one business day.