Home / Trust & Security
Trust & Security
How We Secure the Platform You Trust With Every Identity.
Whiteswan sits in line with every privileged access decision your organization makes. That's a position we don't take lightly — here's how we secure our own platform, and what that means for your data.
Certifications & Standards
Independently Verified, Not Self-Declared.
ISO 27001
SOC 2 Type II
GDPR & HIPAA
Quantum-Safe Standards
Okta · Microsoft · AWS
Platform Security
How We Protect Your Data.
Encryption in Transit and at Rest
Policy decisions, audit logs, and credentials are encrypted end to end, with keys managed separately from the data they protect.
Zero Standing Access, Internally Too
Whiteswan engineers hold no standing access to customer environments. Support access is JIT-elevated, scoped, and logged like every decision our platform makes for you.
Independent Audits
Our controls are assessed annually against SOC 2 Type II and ISO 27001, by auditors we don't choose to be lenient.
Resilient Infrastructure
Multi-region deployment with automated failover, so decision-engine availability doesn't become the thing standing between your users and access.
Continuous Monitoring
Our own infrastructure runs under the same in-line, continuous monitoring philosophy we build for customers — not periodic review, runtime visibility.
Responsible Disclosure
We work with independent security researchers under a coordinated disclosure policy. Report a concern through your account team or security@whiteswansecurity.com.
Your Data, Governed the Way We'd Govern Our Own
Whiteswan processes access decisions and audit metadata — not the underlying application data those systems hold. Data residency, retention, and deletion terms are defined in your master agreement, and enforced the same way our platform enforces every other policy: at runtime, not on request.