Skip to content

Trust & Security

Enterprise trust is a hard constraint.

This page summarizes our security posture for customer security teams, procurement teams, and third-party risk reviews. Detailed artifacts are available to customers and active prospects on request — contact security@swapp.ai.

ISO/IEC 27001:2022 certified
ISO/IEC 27001:2022
Certified ISMS · Certificate No. 1125599 · valid through 2027-12-08 · covers BuildOS Ltd. and SWAPP.IO Inc.

At a glance

Security program ISO/IEC 27001:2022 certified Information Security Management System
Certificate Certificate No. 1125599, valid through 2027-12-08
Cloud infrastructure Google Cloud Platform, United States
Primary data type BIM model data, project metadata, and authentication identifiers
Data residency Customer Data processing is geolocated in the United States
Native BIM files Not transmitted to third-party LLM providers
AI training SWAPP.AI does not use Customer Data to train, fine-tune, or improve general models
MFA / SSO Multi-factor authentication via Descope; SAML and OpenID Connect SSO
Security contact security@swapp.ai

Data handling

Customer-provided drawings, BIM models, files, and project data remain the Customer’s property. Customer Data is used exclusively to provide the SWAPP.AI services requested by the Customer. SWAPP.AI does not require server-side installation in the Customer’s environment or direct access to the Customer’s internal network.

Customer environments and derived data are logically segregated under SWAPP.AI’s ISO/IEC 27001:2022-certified processes. Customer Data is not mixed across customers. SWAPP.AI generally deletes temporary Customer metadata from production systems within 30 days following termination. Customer files remain under the Customer’s control in Autodesk Forma.

Infrastructure and access

SWAPP.AI runs on Google Cloud Platform in the United States. Data is encrypted in transit using TLS 1.2 or higher and at rest using industry-standard controls. Authentication is managed through Descope with multi-factor authentication and SAML / OpenID Connect enterprise SSO. Production access is restricted to authorized personnel under the ISO 27001 program.

AI and LLM usage

Native Customer BIM model files are not transmitted to third-party LLM providers. In limited cases, structured task-specific metadata derived from Customer models may be processed solely to generate requested outputs. SWAPP.AI does not use Customer Data to train, fine-tune, or improve general models, and uses enterprise AI API offerings under terms that restrict provider use of Customer Data for training.

AI outputs are reviewed within the customer’s normal professional workflow. Customers remain responsible for reviewing and approving architectural outputs before use in production, permitting, construction, or regulatory submissions.

Subprocessors

SubprocessorPurposeLocation
Google LLC — Google Cloud PlatformCloud infrastructure: compute, storage, networkingUnited States
Descope Inc.Authentication and identity managementUnited States
Anthropic, PBCLarge language model inferenceUnited States
OpenAI, L.L.C.Large language model inferenceUnited States
Google LLC — Vertex AI / GeminiLarge language model inferenceUnited States

Security review & vulnerability disclosure

SWAPP.AI maintains vulnerability management, patch management, access review, security testing, and incident response processes under its ISO 27001 program. Customers and active prospects may contact security@swapp.ai for certificate copies, independent assessment summaries, detailed subprocessor and AI/LLM disclosures, and security questionnaire responses.

Report suspected vulnerabilities to security@swapp.ai with the affected system, reproduction steps, potential impact, and supporting evidence. We aim to acknowledge valid reports within five business days.

Last updated 2026-05-03. This page is informational and does not modify the applicable agreement between SWAPP.AI and the Customer. See also our Privacy Policy.