Get early access Open the demo

What happens to your prompts.

Aggregation only helps if it does not widen your exposure. Here is exactly what Swurl stores, what it forwards, and what it never does.

Training

Nothing you send through Swurl is used to train any model. We use zero-retention endpoints with every provider that offers them, and where a provider does not, our commercial agreement forbids training on customer data. This is contractual, not a setting you have to find and switch off.

What we store

  • Thread content — stored encrypted so you can come back to it. Deletable per thread or in bulk, and purged from backups within 30 days.
  • Usage metadata — model, token counts, latency, cost, timestamp. This is what powers analytics and billing. Retained 24 months.
  • Prompts in the shared library — visible to your workspace only, never to us in aggregate.

We do not store provider responses separately from the thread, and we do not build any cross-customer index of content.

What providers see

The message you send and the context of the thread, forwarded over TLS to the provider's zero-retention endpoint. Not your name, not your email, not your workspace name, not your billing details. Requests carry an opaque workspace identifier so we can attribute spend, and nothing else.

Encryption

TLS 1.3 in transit. AES-256 at rest, with keys managed in a hardware security module and rotated annually. Database backups are encrypted with a separate key.

Access

Production access is limited to on-call engineers, requires hardware MFA, is time-boxed, and is logged to an append-only store. No engineer can read customer thread content in the course of normal work; a support request that requires it needs your explicit in-product consent, which expires after 24 hours.

Region pinning

On Enterprise, a workspace can be pinned to the United States, the European Union or Australia. Requests then route only to provider endpoints in that region, and thread data is stored in that region. Where a given model has no endpoint in your region it is hidden from the catalogue rather than silently routed elsewhere.

Certifications — where we actually are

Swurl holds no independent security certification yetWe would rather say that plainly than imply otherwise. An observation window is planned to begin once the service carries production traffic, and we will publish the date it starts and the date it completes.

What does exist today: GDPR and UK GDPR commitments as a processor, with a data processing addendum and standard contractual clauses at /dpa/, and a public, versioned subprocessor list at /subprocessors/ with 30 days' notice before anything is added. The controls described on this page are how the system is built. None of them has been examined by a third party.

If your procurement process requires a completed independent audit before signing, we are not ready for you yet. Write to security@swurl.ai anyway and we will come back to you when it exists.

Reporting a vulnerability

Write to security@swurl.ai. We acknowledge within one business day and aim to resolve critical issues within seven. We do not pursue legal action against researchers acting in good faith within the scope published in our security.txt.

Questions your security team needs answered?

We will complete your questionnaire and tell you plainly which controls are built, which are audited, and which are neither.

Contact us