Is this your company?Buyers are checking Swan here. Claim swan.io free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Swan is the easiest way to embed banking features into your product. Via its simple APIs, European companies can integrate banking services (accounts, cards and payments) quickly and easily into their own product.
SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
Auditorraises trust
Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
Report dateraises trust
Add your most recent report period so buyers see how current your SOC 2 is.
Renewal date
Add your renewal window so buyers know your coverage is active.
Other certifications
List your other frameworks (ISO 27001, HIPAA, PCI DSS) the way your trust center does.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Swan SOC 2 compliant?
Swan is SOC 2 compliant. On SOC2C this listing is Listed.
Can I use Swan's SOC 2 for a vendor risk assessment?
Yes. Swan's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Swan penetration tested?
Swan hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Is Swan secure?
Security isn't a single yes/no, but Swan is SOC 2 compliant. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Swan have a bug bounty or vulnerability disclosure program?
Swan hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@swan.io or via a /security page (Swan lists a security contact).
Who are Swan's subprocessors?
Swan lists 12 subprocessors on its trust center, including Amazon Web Services, Idemia, Wise, Monext 3DS, Checkout (Ubble). Buyers use this for fourth-party risk review.
Where does Swan host or store data?
Swan hosts on AWS. Data residency details are on its trust center.
Where is Swan's trust center or security page?
Swan's trust center is at https://trust.swan.io. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.
Where is Swan's infrastructure located?
All customer content is hosted in Amazon AWS Public Cloud. Our whole infrastructure is hosted on AWS Public Cloud located in eu-west-1 zone, Ireland. Where disasters would occur causing damage against AWS Data center, Swan would be able to redeploy its infrastructure onto a distinct hosting location as infrastructure-as-code mechanisms are in use.
How does Swan manage vulnerabilities?
Swan runs an ongoing security management program to ensure that its security measures are aligned with the level of risk. This program is guided by risk assessments and utilizes both internal resources and specialized security third-parties. It includes: - Black box penetration testing at least twice a year - Bug bounty programs - Red team exercises - Continuous vulnerability scanning - Systematic peer reviews for each code release - Developers are trained on an annual basis and during onboarding against common development vulnerabilities, using OWASP and Mitre CWE recommendations - The security team performs internal architecture reviews for projects and new features that are sensitive to security concerns Swan aims to address vulnerabilities within 14 days for critical severity, 30 days for high severity, and 60 days for medium severity.
What are Swan cybersecurity certifications and compliance standards?
As a financial institution, Swan is complying with DORA (Digital Operational Resilience Act). We are continuously working to maintain our compliance level with DORA. Swan is also certified for ISO/IEC 27001:2022. As the holder of an EMI license, also licensed to provide payment services, Swan comply with all applicable regulatory requirements set out in PSD2, including : strong governance, capital requirements, internal control and risk management, etc.
Is Swan PCI DSS certified?
Swan is not PCI DSS certified because it is not necessary for our business. Swan does not store, process or transit cardholder data (payment card numbers). For payment services, Swan relies on Monext to handle cardholder data and process payments. Monext is PCI DSS certified. For card issuing services, Swan relies on Idemia to handle the issuing of payment cards. Idemia is PCI DSS certified. Swan is currently working on an accept payments project with Checkout as a Acquirer & Gateway. Checkout is PCI DSS certified, and for the scope of this project, Swan is PCI DSS SAQ A-EP compliant.
Does Swan encrypt data at rest?
All customer data is encrypted at rest at any time. We currently use AWS's standard mechanisms and AES 256 is the main standard in use. Backups are also encrypted through AWS's standard mechanisms.
How does Swan protect data in transit?
All Swan web properties have mandatory encryption in transit. We use HSTS and HTTPS with TLS1.2 version minimum for all API data flows.
How does Swan manage vendor security?
Vendors are all identified via the procurement process that includes reviews from our Security team. They are categorized according to their risk level, and security due diligence controls are conducted accordingly. These controls may include requirements for security features (such as SSO capabilities), certifications, and the presentation of audit results.
Does Swan notify its customer in case of a data breach?
Swan commits to promptly notify its customers upon becoming aware of any data breach that affects them. Such communication includes the following information: - High-level description of the incident - Type of data that is involved - Number of impacted accounts, if relevant - Ongoing and planned corrective actions The incident response process cover notification to regulatory authorities where relevant. Criteria for notifying partners is the existence of a proved impact affecting the partner (including in particular without be limited to: data violation or any fraud-related incident that would affect account(s) on their project).
What are Swan's business continuity and disaster recovery practices?
Swan relies on Amazon AWS Platforms' business continuity features. The infrastructure is deployed in such a way that it can sustain the loss of one availability zone without any noticeable impact. If an entire cloud region was to unavailable, Swan can restore the service in another region in a reasonable time thanks to Infrastructure-as-Code and backups in other regions.