Security
Last updated: July 18, 2026
Content IQ handles brand, label, and claims material that pharmaceutical and medtech teams depend on for regulated commercial content. This page describes the technical and organizational measures SwishX uses to protect that material, at every layer of the platform.
1. Our approach to security
Security at SwishX is organized around three commitments: protect Customer Content as if it were our own most sensitive material, minimize what we collect and how long we keep it, and build so that a security or availability incident is detected and acted on quickly rather than discovered late. These commitments apply across our infrastructure, our application, our AI generation pipeline, and our own internal operations.
2. Infrastructure & hosting
Content IQ runs on infrastructure provided by major cloud providers (including AWS), inside virtual private networks with segmented subnets separating public-facing services from application and data layers. Production environments are logically isolated from development and staging environments, and Customer Content is never used in non-production environments. Infrastructure is provisioned and versioned as code, reviewed prior to deployment, and monitored continuously for configuration drift.
3. Encryption
Data is encrypted in transit using TLS 1.2 or higher across all client and internal connections, and encrypted at rest using AES-256 or an equivalent standard. Encryption keys are managed through a dedicated key-management service with restricted access and rotation policies, separate from the systems that store the data they protect.
4. Access controls & authentication
Access to Content IQ and to production systems is governed by the principle of least privilege. We support:
- Single sign-on (SSO/SAML) for enterprise Customer accounts;
- Multi-factor authentication for all internal SwishX access to production systems;
- Role-based access control within each Customer workspace, configurable by that Customer鈥檚 administrators;
- Comprehensive audit logging of authentication events, permission changes, and access to Customer Content; and
- Periodic access reviews to remove unnecessary or stale permissions.
5. Application security
Our software development lifecycle includes peer code review, automated dependency and static-analysis scanning on every change, and staged rollouts with monitoring before a change reaches all customers. We engage independent third parties to perform penetration testing of the application and infrastructure on a recurring basis, and we remediate findings according to severity-based timelines. We also operate a vulnerability disclosure program (Section 10) so external researchers can report issues responsibly.
6. Compliance & certifications
SwishX is SOC 2 Type II compliant, audited against the AICPA Trust Services Criteria for security, availability, and confidentiality, and our security program is further aligned with common industry frameworks such as the NIST Cybersecurity Framework. Customers with specific compliance or audit requirements (including requests for our SOC 2 report, DPA terms, or other certification documentation) are welcome to contact our security team at any time; see Section 14.
7. Sub-processor management
We use a limited number of vetted sub-processors to provide hosting, AI model inference, payment processing, and related infrastructure. Each sub-processor is subject to a written data processing agreement imposing confidentiality, security, and data-handling obligations consistent with our own commitments to Customers, and is reviewed before onboarding and periodically thereafter. A current sub-processor list is available on request at security@swishx.com.
8. Business continuity & disaster recovery
Customer Content is backed up on a regular, automated schedule, with backups encrypted and stored separately from primary production data. We maintain documented recovery procedures with target recovery time and recovery point objectives, and we test those procedures periodically. Infrastructure is deployed across multiple availability zones to reduce the impact of a single infrastructure failure.
9. Incident response & breach notification
We maintain a documented incident response plan covering detection, containment, eradication, and recovery, with a designated on-call team monitoring production systems. In the event of a security incident affecting Customer Content, we will notify affected Customers without undue delay and, where required by applicable law (including the 72-hour notification expectation under the GDPR), within the timeframe the law requires, along with the information reasonably available to us about the nature and impact of the incident.
10. Vulnerability disclosure program
We welcome reports from security researchers who believe they have found a vulnerability in our Services. If you report a vulnerability in good faith, in accordance with the guidelines below, we will not pursue legal action against you for that research:
- Provide enough detail for us to reproduce and validate the issue, including steps, affected URLs or endpoints, and any proof-of-concept material;
- Avoid accessing, modifying, or deleting data that is not your own, and avoid degrading the availability of the Services for other users;
- Give us a reasonable period to investigate and remediate before any public disclosure; and
- Report the issue directly to us rather than to a third party.
Send reports to security@swishx.com. We aim to acknowledge reports within two business days.
11. Employee security practices
All SwishX personnel undergo background screening consistent with local law prior to being granted access to production systems, complete security and data-handling training at onboarding and on a recurring basis, and are bound by confidentiality obligations covering Customer Content. Access to production systems and Customer Content is granted on a least-privilege, need-to-know basis and is revoked promptly upon role change or departure.
12. AI & model security
Customer Content submitted to Content IQ's generation pipeline, including Brand Dossier material and briefs, is logically isolated per Customer and is not used to train foundation models on behalf of our AI infrastructure providers. We contractually restrict our model providers from retaining or training on Customer Content beyond what is necessary to deliver the requested generation, and we apply the same encryption and access-control standards described above to data in transit to and from model providers.
13. Customer security controls
Customer administrators can configure a number of controls directly within Content IQ, including SSO enforcement, role-based permissions, session timeout policies, and export of audit logs covering activity within their workspace. We recommend Customers review these settings as part of their own internal security and compliance processes.
14. Contact & report a vulnerability
For security questions, sub-processor lists, compliance documentation requests, or to report a vulnerability, contact:
SwishX Security Team
security@swishx.com