Is this your company?Buyers are checking Swarm here. Claim swarm.engineering free to control the listing, earn the badge buyers trust, and see who's evaluating you.
SWARM offers a Software-as-a-Service platform using next generation AI to save costs, reduce waste, and deliver environmental benefits. Our platform is the primary way for organizations to discover, define, and solve challenges. We are changing the way the world thinks about problem-solving, and we call our approach Challenge Engineering®. Our focus is to help people solve operational challenges for multi-million-dollar savings.
SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
Auditorraises trust
Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
Report dateraises trust
Add your most recent report period so buyers see how current your SOC 2 is.
Renewal date
Add your renewal window so buyers know your coverage is active.
Other certifications
List your other frameworks (ISO 27001, HIPAA, PCI DSS) the way your trust center does.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Swarm SOC 2 compliant?
Swarm is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Swarm SOC 2 Type I or Type II?
Swarm is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Swarm's SOC 2 for a vendor risk assessment?
Yes. Swarm's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Swarm penetration tested?
Swarm hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Can I get Swarm's SOC 2 report?
Swarm's SOC 2 report is available on request. Request access through SOC2C and we coordinate the company-side NDA and delivery.
Is Swarm secure?
Security isn't a single yes/no, but Swarm is SOC 2 Type II compliant. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Swarm have a bug bounty or vulnerability disclosure program?
Swarm hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@swarm.engineering or via a /security page (Swarm lists a security contact).
Who are Swarm's subprocessors?
Swarm lists 12 subprocessors on its trust center, including Microsoft Azure, Couchbase, Datadog, Tableau, Calendly. Buyers use this for fourth-party risk review.
Where does Swarm host or store data?
Swarm hosts on Azure, and handles Customer personally identifiable information, Credit card information, Personal health information. Data residency details are on its trust center.
Where is Swarm's trust center or security page?
Swarm's trust center is at https://trust.swarm.engineering. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.
Is my data secure with SWARM?
Security is a top priority at SWARM, and we put the same care in protecting our customers' and users' data as we do with our data and information. We utilize many tools, processes, procedures, and protections to support these efforts such as firewalls, encryption, training, monitoring / alerts, and detection solutions.
Do you have security policies in place?
SWARM has developed a comprehensive set of security policies covering a range of topics. These policies are updated frequently and are required to be read and approved by all employees and key contractors.
How do you monitor for security breaches?
SWARM uses a variety of monitoring and alert tools to prevent, identify, and resolve any potential security incidents. SWARM utilizes Azure and Datadog for monitoring, logging, and alerting, and SWARM also has a variety of security features enabled on its software tools to alert for suspicious logins or activity.
How do I report a potential security issue?
You can reach out to our customer support team by using our help messenger within the SWARM application, or you can email our security team at security@swarm.engineering.
Where are your servers located?
SWARM is a fully cloud-based service hosted by Microsoft Azure with production servers located in the United States across multiple availability zones. We may provide alternative server locations for enterprise customers located outside of the United States.
Do you support Single Sign-On (SSO) or MFA?
We utilize Okta for identify verification and login services for the SWARM platform. We can work with enterprise clients to support SSO (e.g., SAML) or MFA requirements based on their needs.
Do you encrypt data at rest?
Yes, we encrypt confidential customer data at rest and in transit over public networks in accordance with SWARM's Cryptography Policy.
Is there an SLA for resolving identified security issues?
Yes, we outline our SLAs in Master Service Agreements (MSAs) with enterprise customers.
Is my data being used to train AI models?
No, our users' data is not utilized to train any AI models.
Have SWARM team members signed confidentiality agreements?
Yes, all SWARM employees and contractors have signed confidentiality agreements to ensure privacy and confidentiality to SWARM and its users.
Does SWARM have an office or on-site premises?
No, SWARM is a fully remote company that is fully hosted in the cloud.
Does SWARM conduct vulnerability and penetration testing?
Yes, SWARM actively scans its cloud systems and code for vulnerabilities and penetration testing is performed by an external independent provider at least annually.