Last updated: May 2026
Contents
We treat security as a product requirement and describe only controls that are implemented or operationally required by the current service.
Current codebase controls include:
We protect data through access control, provider security controls, encrypted transport, and restricted operational access.
The dashboard includes an account deletion route for signed-in users. It deletes app-owned project, quote, and privacy request records associated with the authenticated email address.
External OAuth accounts remain managed by the OAuth provider.
If we identify a personal-data breach or security incident, we investigate, contain, document, and notify affected parties or authorities where required by applicable law.
Report suspected vulnerabilities to info@swarpfoundation.com with enough detail to reproduce and validate the issue.
We do not claim ISO 27001 certification, completed third-party audits, or formal penetration-test certification unless separately published. Security claims should remain tied to implemented controls and documented provider guarantees.
If you have any questions about this policy or want to exercise your rights, contact us at:
Email: info@swarpfoundation.com
Address: Viale Tunisia 22, 20124, Milano (MI), Italy