Security and compliance

Your leads stay in the EU.

The short version for your IT department. The long version, with documents, is one email away.

Request the security pack

Data residency

Production data is stored and processed in EU data centres (Google Cloud, europe-west1). Backups stay in the EU.

GDPR

Swopi s.r.o. is a Czech company. We act as processor for your leads and cards. A data processing agreement with a subprocessor list is available on request.

Authentication

Email, Google and Microsoft sign-in. Single sign-on with Microsoft Entra ID for organisations, enforceable for all members. Sessions are short lived and revocable.

Provisioning

SCIM 2.0 creates and removes users and cards automatically from your identity provider. Roles: owner, admin, member.

Encryption

TLS 1.2 or newer in transit. Encryption at rest on Google Cloud. Secrets are stored in managed vaults, never in code.

AI processing

Enrichment and follow-up drafts run through AI providers under data processing terms. Your data is not used to train models.

Monitoring

Error tracking, uptime monitoring and audit logs for team actions. Incidents are communicated to admins by email.

Documents

Security questionnaire answers, DPA, subprocessor list and a penetration test summary on request. SOC 2 and ISO 27001 are on the roadmap.