Dashboard

Security

Security you don’t have to think about

Your account, your apps and your data are protected from the first prompt. Here’s exactly how, in plain English.

Report a vulnerability
  • Database hosted in the EU
  • Two-step sign-in
  • Nightly encrypted backups

Private while you build

Previews need a sign-in and a seat in your workspace. Every table in our database is locked down with row-level security.

Your keys stay secret

Paste a key into chat and Swarmz warns you first. Credentials are encrypted and scrubbed from AI logs.

Nothing drastic without you

Dropping or emptying a table always asks you first. So do connector writes, by default.

Always recoverable

Encrypted nightly backups kept for 30 days, plus one-click version history.

Your account

Keep your account yours

Your Swarmz account is the key to everything you build, so sign-in is guarded at every step, with Cloudflare Turnstile keeping bots out.

  • Two-step sign-in with an authenticator app and recovery codes
  • Once it’s on, password and social sign-ins both need it
  • Google, Apple, GitHub or email, plus SAML SSO on Business
  • See every active session and sign out the rest
  • An email alert whenever a new device signs in

Your team

The right access for everyone

Give each person the role they need. Roles are enforced in the database itself, not just hidden in the interface.

  • Owner, Admin, Editor and Viewer roles
  • Keep a project personal or share it with the team
  • Work-in-progress previews need a seat in your workspace
  • Publish publicly, or privately to your team on Business
  • Any support access by our team is logged

Data location

Where your data lives

Your account and our database are hosted in Ireland. Your projects are built and previewed on our servers in Germany.

  • Your account and our databaseIreland, EUHosted by Supabase
  • Building and previewing your projectsNuremberg, GermanyOur servers at Hetzner
  • Your published appsWorldwide, close to your visitorsServed by Cloudflare’s global network
  • Your app’s own databaseYour choice of 16 regionsWith Swarmz Cloud

Put your app’s data near your customers

When your app gets its own database, you pick where it lives. The nearest region is chosen for you.

Americas

  • Virginia
  • Ohio
  • N. California
  • Montreal
  • São Paulo

Europe

  • Ireland
  • London
  • Paris
  • Frankfurt
  • Zurich
  • Stockholm

Asia-Pacific

  • Mumbai
  • Singapore
  • Sydney
  • Tokyo
  • Seoul

Some services, such as the AI models and parts of our web app, run in the United States. The full picture is in our Privacy Policy and the provider list below.

Encryption

Your credentials, encrypted twice

Everything travels over HTTPS. Our database, file storage and backups are encrypted at rest, and the keys and tokens you connect are encrypted again by us before they’re stored.

That means the accounts you connect, like Slack or Notion, are stored scrambled rather than as readable text.

What’s encrypted, and how

On by default
  • Everything you send

    Travels over HTTPS, with HSTS preload on our domains

    TLS
  • Our database and file storage

    Encrypted at rest by Supabase

    AES-256
  • Connector credentials

    Encrypted again by us before they’re saved

    AES-256-GCM
    You entersk_live_51Nx8Qp…we storev2:Jx9fA7cL0eWq…kQ2=
  • Access tokens and sign-in codes

    Stored only as a one-way hash, never the real thing

    SHA-256
  • Nightly backups

    Encrypted, then kept for 30 days

    AES-256

AI and your data

What happens to your prompts

Swarmz builds with AI models from OpenAI and Anthropic. Here’s what they receive, and what we keep.

  • OpenAI and Anthropic don’t train on itBoth say data sent through their APIs isn’t used to train their models by default.
  • Asked not to store responsesOur requests tell OpenAI not to keep responses for later. Its abuse logs are kept up to 30 days.
  • A pseudonymous ID, not your accountOpenAI sees a stand-in ID for abuse checks, never your Swarmz account ID.
  • Secrets scrubbed from AI logsKeys, tokens and connection strings are removed from our AI logs before they’re saved.

Your chats are saved with your project so you can come back to them. What OpenAI and Anthropic do with API data is set by their own policies.

Paste a key into chat and Swarmz stops you, then offers a secure form instead.

Your apps

Guardrails for everything you build

The AI moves fast. Wiping data always waits for your OK, and anything it sends to your connected apps asks first by default.

Destructive changes

Wiping data always asks you

Dropping or emptying a table stops for your OK, whatever your settings. That safety net can’t be switched off.

AI permissions

You decide what the AI can change

Let it update your app’s database as it builds, or review every change before it runs.

Connectors

Connector writes ask first

Reading from Slack or Notion just runs. Posting or changing anything asks for your approval by default.

Final checks

It checks its own work

Before it says done, Kernel 1 checks code style, types, your preview and runtime errors. If something fails, it tries to fix it, then tells you straight.

Payments & backups

Safe payments. Nightly backups

Payments

Card details never touch our servers

Checkout is hosted by Stripe, a PCI DSS Level 1 provider. Payments inside your apps run on Stripe Connect.

Backups

Backed up every night

Every project is backed up nightly, encrypted, and kept for 30 days. Roll back any change yourself from version history.

Privacy

Your data, your call

You own what you build, and you decide what happens to your data. We don’t sell it, and we’re registered with the UK ICO (ZC161704).

  • Delete your account yourself, instantly, from Settings
  • Copies in our backups age out within 30 days
  • Analytics cookies stay off until you say yes
  • Global Privacy Control signals are honoured
  • Your UK GDPR rights, one email away: privacy@swarmz.net

Infrastructure

Built on trusted infrastructure

Our database, servers and payments run on providers certified to standards like SOC 2 and ISO 27001. We name every provider, so you know exactly who’s involved.

A rack of servers with green status lights in a quiet data centre

Supabase

Hosts our database, sign-in and file storage

SOC 2 Type 2ISO 27001

Hetzner

Runs the servers that build and preview your projects

ISO/IEC 27001:2022

Stripe

Handles every card payment

PCI DSS Level 1SOC 2

Certifications belong to our providers, not to Swarmz. Cloudflare and Vercel also run parts of Swarmz; see the full list below.

Every provider we use today

A plain-English list of the companies that run parts of Swarmz, taken from how the product is built right now. It’s here so you can see who’s involved. It isn’t a contractual subprocessor list.

  • SupabaseIreland (EU). Cloud apps: the region you chooseOur database, sign-in and file storage. Also the backend for each Swarmz Cloud app
  • HetznerNuremberg, GermanyThe servers that build and preview your projects, and the source of nightly backups
  • CloudflareGlobal networkSign-in, AI streaming, private previews, published apps, bot checks and DNS
  • VercelEU and United StatesHosting for the swarmz.net web app
  • OpenAIUnited StatesThe AI that builds your app, plus images, transcription and web search
  • AnthropicUnited StatesAI for design directions, plans and variations
  • StripeGlobalPlan payments, top-ups and Swarmz Payments
  • ResendUnited StatesAccount and notification emails
  • SentryEUError monitoring, only with your consent in the browser
  • PostHogEUProduct analytics, only with your consent
  • Google IrelandEUGoogle Analytics in consent mode. Ad signals only after you opt in
  • Better StackNot specifiedOur status page
  • GitHubUnited StatesOptional sync of your code to your own repository
  • FirecrawlUnited StatesOptional fetching of web pages you ask the AI to read

Report a problem

Found something? Tell us

A security vulnerability

Found a weakness in Swarmz? Email us privately with the steps to reproduce it, and please don’t share it publicly first.

Abuse, copyright or trademark

Report an app or content made with Swarmz, or appeal a decision. Every report gets its own case reference.

Privacy and your data

Ask for a copy of your data, use any of your UK GDPR rights, or ask how we handle something.

Where is my data stored?
Your account and our main database are hosted by Supabase in Ireland (EU), and your projects are built and previewed on our servers in Nuremberg, Germany. Published apps are served from Cloudflare’s global network. If your app uses Swarmz Cloud, you choose where its database lives from 16 regions. Some services, such as the AI models and parts of our web app, run in the United States.
Who can see my projects?
Your workspace. A project is shared with your workspace unless you keep it personal, and work-in-progress previews need a sign-in and a seat in that workspace. Nothing is public until you publish it, and on the Business plan you can publish privately to your team.
Can we use single sign-on (SSO)?
Yes, on the Business plan and up. Connect any SAML 2.0 identity provider, with presets for Google Workspace, Microsoft Entra ID, Okta and Auth0. You verify your domain with a DNS record, can add new teammates automatically, and can require SSO for everyone on the domain.
What happens when I delete my account?
Deletion is immediate: your projects, files, chats, profile and sign-in are removed. Copies held in our encrypted nightly backups age out within 30 days.
Are you SOC 2 certified?
Not yet. Swarmz doesn’t hold its own security certifications today. We build on providers that do: Supabase (SOC 2 Type 2, ISO 27001), Hetzner (ISO/IEC 27001) and Stripe (PCI DSS Level 1).

Build on solid ground

Start free with 5 credits every day. No card needed.

See pricing