Security & Trust at Swazzy

Security you can trust. Governance you can rely on. Resilience built in.

At Swazzy, security is not an afterthought — it is a core part of how we design, deliver, and operate our services. We protect customer data, reduce cyber risk, and build resilient systems so our customers can operate with confidence.

This page provides a transparent overview of how Swazzy approaches information security and trust.

Our Security Commitment

Swazzy is committed to:

  • Protecting customer data and information assets
  • Preventing unauthorised access, loss, or misuse of information
  • Maintaining resilient services that withstand cyber threats
  • Continuously improving our security posture as threats evolve

Security is governed at an executive level and embedded into our daily operations.

Our Security Framework

Swazzy operates a structured security program aligned with recognised industry frameworks:

  • ISO/IEC 27001 – Information Security Management principles
  • ACSC Essential Eight – Australia’s baseline cyber security framework

These frameworks guide how we manage risk, implement controls, and review effectiveness.

How We Protect Your Data

 

Identity & Access Management

  • Unique user accounts for all personnel
  • Multi-Factor Authentication (MFA) for remote and privileged access
  • Role-based access aligned to job responsibilities
  • Immediate access removal through formal joiner–mover–leaver processes

Data Protection

  • Defined data classification and handling standards
  • Encryption for sensitive data in transit and at rest
  • Access restricted on a need-to-know basis

Cyber Threat Protection

Swazzy applies layered cyber security controls to protect against modern threats:

  • Application control to prevent unauthorised software
  • Regular patching of operating systems and applications
  • Endpoint protection and malware detection
  • Hardened user applications and browsers

These controls significantly reduce the risk of ransomware and common attack techniques.

Ransomware Resilience & Recovery

To protect against ransomware and service disruption, Swazzy:

  • Performs regular, encrypted backups
  • Maintains offsite and immutable backup copies
  • Isolates backup systems from production credentials
  • Tests recovery procedures regularly

This ensures we can restore systems and data quickly when incidents occur.

Incident Response & Transparency

Swazzy maintains a documented and tested incident response capability:

  • Rapid identification, containment, and recovery processes
  • Clear escalation and communication procedures
  • Post-incident reviews to strengthen controls

Where required, customers are notified in accordance with contractual and regulatory obligations.

Third-Party & Supplier Security

We manage third-party risk by:

  • Assessing suppliers based on access and security risk
  • Defining security obligations contractually
  • Limiting supplier access to what is necessary to deliver services

Training & Security Awareness

People are critical to security. Swazzy ensures:

  • Regular security awareness training for all personnel
  • Education on phishing, social engineering, and data protection
  • Clear channels for reporting security concerns

Continuous Assurance & Improvement

Our security program is continually reviewed and improved through:

  • Ongoing risk assessments
  • Internal security audits
  • Executive management reviews
  • A documented roadmap to higher cyber maturity

Responsible Disclosure

We welcome responsible disclosure of security vulnerabilities.

If you believe you have identified a security issue, please report it responsibly via:

Emailsecurity@swazzy.co

Learn more about our Responsible Disclosure Policy.

Need More Information? 

We understand that every customer has different security requirements. If you have specific questions or require additional assurance, our team is happy to help.

👉 Contact us to discuss your security requirements

 
 
 
 
 
 
Scroll to Top