Trust & Security Center

Your Data is Your Business. We Keep It That Way.

Bank-level encryption, strict data isolation, and uncompromising safety benchmarks — built in from day one, not bolted on.

Data Isolation

Your data trains your assistant. No one else's.

Every workspace is isolated by tenant. Each query is scoped to your organisation, and we are progressively adding database-level row-level security on top of that — starting with the most sensitive tables — so isolation is enforced in more than one place. The proprietary data you share — brand voice, customer lists, internal documents — is used only to make your assistants better.

It is never pooled with other customers' data, never shared, and never used to train anyone else's assistant. When you leave, it's permanently deleted within 30 days.

Safe Content Benchmark

A safety layer nothing can switch off.

Every assistant is governed by the Be More Swan Safe Content Benchmark — a safety layer carried at the highest priority in every system prompt. It cannot be disabled, overridden or bypassed by any workspace setting, or by your own instructions to an assistant.

It works alongside two other layers: prompts are screened before generation, and drafts land in a review queue for a person to approve. Together they make unsafe or off-brand output far less likely — but no automated safety layer catches everything, which is exactly why human review is the default.

Infrastructure

Hardened hosting, watched around the clock.

Be More Swan runs on secure, managed cloud infrastructure with UK/EU data residency, continuous monitoring, and regular penetration testing. All traffic is encrypted with TLS 1.3 and all storage with AES-256.

The API keys and OAuth credentials that connect your business tools are stored with AES-256-GCM application-layer encryption. Plaintext credentials are never logged and never returned to a browser.

Built to recognised security standards

UK / EU GDPR Compliant SOC 2-Aligned Controls TLS 1.3 In Transit AES-256 At Rest PCI DSS Payments via Stripe

Compliance Details

Last updated: · Reviewed quarterly

GDPR Compliance: Be More Swan acts in two roles under UK GDPR / EU GDPR, as most business software does. For the business data you put into your workspace — your content, your contacts, and the data we read from the accounts you connect — we are a Data Processor, handling it on your instructions and for no other purpose. For your own account, login and billing data, and for running and securing the platform itself, we are a Data Controller. A Data Processing Agreement covering the processor role is presented to you in-product when you set up your organisation, and your acceptance is recorded; you can re-read it any time from your account settings. If you need a countersigned copy for your own records, use the request form below. Our full Privacy Policy is available at /privacy.html. For erasure requests, please email hello@bemoreswan.com.

Data Residency

Your primary workspace data is stored in the United Kingdom / European Economic Area — our managed PostgreSQL database sits in an EU region, video rendering runs in AWS eu-west-2 (London), and Netlify serves the application through UK/EU edge nodes. Uploaded and generated media is held in Cloudflare R2 object storage, which is globally distributed rather than pinned to a single region. Being straight with you: some processing does happen in the United States, because the AI model providers, our payment processor and our transactional email provider are US-based. Every one of those transfers runs under adequate safeguards as required by UK GDPR Article 46 — Standard Contractual Clauses, or the UK–US Data Privacy Framework in Stripe's case — supported by a documented Transfer Impact Assessment and minimisation of the data sent to model APIs. The table below names each provider and where it sits.

Sub-Processors

Be More Swan uses the following third-party sub-processors to deliver its services. Each is assessed for GDPR compliance before we adopt it, and we rely on the provider's data processing terms for every transfer of personal data. Where a row is marked "copy on request", email us and we will send the current agreement. Several are used only if you choose to connect that service.

Sub-Processor Purpose Location DPA / Security
Anthropic AI language model inference — the primary model behind your assistants' drafting, chat and review USA (SCCs applied) anthropic.com/legal/privacy
OpenAI Content moderation screening and product tour narration USA (SCCs applied) openai.com/enterprise-privacy
Voyage AI Embedding of knowledge-base content so assistants can search it USA (SCCs applied) Copy on request
fal.ai AI image and video generation from your prompts USA (SCCs applied) Copy on request
Stripe Payment processing & billing USA / UK (SCCs applied) stripe.com/gb/privacy
Resend Transactional email delivery USA (SCCs applied) resend.com/legal/privacy-policy
Netlify Hosting, serverless functions, CDN USA / EU edge nodes netlify.com/gdpr-ccpa
Neon Managed PostgreSQL — where your workspace data is stored EU (eu-west) — no US transfer for stored data Copy on request
Cloudflare R2 object storage — uploaded files and generated media Global distributed network cloudflare.com/trust-hub/gdpr
Amazon Web Services Lambda video rendering for post and Short overlays UK (eu-west-2, London) aws.amazon.com/compliance/gdpr-center
Twilio SendGrid Inbound email parsing — turns mail sent to us into support and CRM records USA (SCCs applied) twilio.com/legal/privacy
Serper Web search for outbound lead discovery USA (SCCs applied) Copy on request
Google Only where you connect a Google account — Search Console metrics, Drive and calendar data, and sending from your own inbox USA / global (SCCs applied) cloud.google.com/terms/dpa
Canva Only where you connect Canva — importing your designs as post media Australia / global (SCCs applied) canva.com/policies/privacy-policy
Pexels Stock photo and video search — receives search terms, not your workspace data Germany (EU) pexels.com/privacy-policy

Encryption Standards

Penetration Testing

Be More Swan undergoes regular security assessments. Our last penetration test was conducted in Q2 2026. A summary report is available on request to enterprise customers — please email hello@bemoreswan.com with the subject "Security Report Request".

Data Retention

Request a Data Processing Agreement

Enterprise customers and partners may request a signed DPA for their records. Complete the form below and we'll respond within 2 business days.

Happy with how we handle your data?

Pick a plan and hire your first assistant. Rolling monthly — cancel any time.