Trust & Security
Enterprise trust is a hard constraint.
This page summarizes our security posture for customer security teams, procurement teams, and third-party risk reviews. Detailed artifacts are available to customers and active prospects on request — contact security@swapp.ai.
At a glance
| Security program | ISO/IEC 27001:2022 certified Information Security Management System |
|---|---|
| Certificate | Certificate No. 1125599, valid through 2027-12-08 |
| Cloud infrastructure | Google Cloud Platform, United States |
| Primary data type | BIM model data, project metadata, and authentication identifiers |
| Data residency | Customer Data processing is geolocated in the United States |
| Native BIM files | Not transmitted to third-party LLM providers |
| AI training | SWAPP.AI does not use Customer Data to train, fine-tune, or improve general models |
| MFA / SSO | Multi-factor authentication via Descope; SAML and OpenID Connect SSO |
| Security contact | security@swapp.ai |
Data handling
Customer-provided drawings, BIM models, files, and project data remain the Customer’s property. Customer Data is used exclusively to provide the SWAPP.AI services requested by the Customer. SWAPP.AI does not require server-side installation in the Customer’s environment or direct access to the Customer’s internal network.
Customer environments and derived data are logically segregated under SWAPP.AI’s ISO/IEC 27001:2022-certified processes. Customer Data is not mixed across customers. SWAPP.AI generally deletes temporary Customer metadata from production systems within 30 days following termination. Customer files remain under the Customer’s control in Autodesk Forma.
Infrastructure and access
SWAPP.AI runs on Google Cloud Platform in the United States. Data is encrypted in transit using TLS 1.2 or higher and at rest using industry-standard controls. Authentication is managed through Descope with multi-factor authentication and SAML / OpenID Connect enterprise SSO. Production access is restricted to authorized personnel under the ISO 27001 program.
AI and LLM usage
Native Customer BIM model files are not transmitted to third-party LLM providers. In limited cases, structured task-specific metadata derived from Customer models may be processed solely to generate requested outputs. SWAPP.AI does not use Customer Data to train, fine-tune, or improve general models, and uses enterprise AI API offerings under terms that restrict provider use of Customer Data for training.
AI outputs are reviewed within the customer’s normal professional workflow. Customers remain responsible for reviewing and approving architectural outputs before use in production, permitting, construction, or regulatory submissions.
Subprocessors
| Subprocessor | Purpose | Location |
|---|---|---|
| Google LLC — Google Cloud Platform | Cloud infrastructure: compute, storage, networking | United States |
| Descope Inc. | Authentication and identity management | United States |
| Anthropic, PBC | Large language model inference | United States |
| OpenAI, L.L.C. | Large language model inference | United States |
| Google LLC — Vertex AI / Gemini | Large language model inference | United States |
Security review & vulnerability disclosure
SWAPP.AI maintains vulnerability management, patch management, access review, security testing, and incident response processes under its ISO 27001 program. Customers and active prospects may contact security@swapp.ai for certificate copies, independent assessment summaries, detailed subprocessor and AI/LLM disclosures, and security questionnaire responses.
Report suspected vulnerabilities to security@swapp.ai with the affected system, reproduction steps, potential impact, and supporting evidence. We aim to acknowledge valid reports within five business days.
Last updated 2026-05-03. This page is informational and does not modify the applicable agreement between SWAPP.AI and the Customer. See also our Privacy Policy.