Security & Trust at Swazzy
Security you can trust. Governance you can rely on. Resilience built in.
At Swazzy, security is not an afterthought — it is a core part of how we design, deliver, and operate our services. We protect customer data, reduce cyber risk, and build resilient systems so our customers can operate with confidence.
This page provides a transparent overview of how Swazzy approaches information security and trust.
Our Security Commitment
Swazzy is committed to:
- Protecting customer data and information assets
- Preventing unauthorised access, loss, or misuse of information
- Maintaining resilient services that withstand cyber threats
- Continuously improving our security posture as threats evolve
Security is governed at an executive level and embedded into our daily operations.
Our Security Framework
Swazzy operates a structured security program aligned with recognised industry frameworks:
- ISO/IEC 27001 – Information Security Management principles
- ACSC Essential Eight – Australia’s baseline cyber security framework
These frameworks guide how we manage risk, implement controls, and review effectiveness.
How We Protect Your Data
Identity & Access Management
- Unique user accounts for all personnel
- Multi-Factor Authentication (MFA) for remote and privileged access
- Role-based access aligned to job responsibilities
- Immediate access removal through formal joiner–mover–leaver processes
Data Protection
- Defined data classification and handling standards
- Encryption for sensitive data in transit and at rest
- Access restricted on a need-to-know basis
Cyber Threat Protection
Swazzy applies layered cyber security controls to protect against modern threats:
- Application control to prevent unauthorised software
- Regular patching of operating systems and applications
- Endpoint protection and malware detection
- Hardened user applications and browsers
These controls significantly reduce the risk of ransomware and common attack techniques.
Ransomware Resilience & Recovery
To protect against ransomware and service disruption, Swazzy:
- Performs regular, encrypted backups
- Maintains offsite and immutable backup copies
- Isolates backup systems from production credentials
- Tests recovery procedures regularly
This ensures we can restore systems and data quickly when incidents occur.
Incident Response & Transparency
Swazzy maintains a documented and tested incident response capability:
- Rapid identification, containment, and recovery processes
- Clear escalation and communication procedures
- Post-incident reviews to strengthen controls
Where required, customers are notified in accordance with contractual and regulatory obligations.
Third-Party & Supplier Security
We manage third-party risk by:
- Assessing suppliers based on access and security risk
- Defining security obligations contractually
- Limiting supplier access to what is necessary to deliver services
Training & Security Awareness
People are critical to security. Swazzy ensures:
- Regular security awareness training for all personnel
- Education on phishing, social engineering, and data protection
- Clear channels for reporting security concerns
Continuous Assurance & Improvement
Our security program is continually reviewed and improved through:
- Ongoing risk assessments
- Internal security audits
- Executive management reviews
- A documented roadmap to higher cyber maturity
Responsible Disclosure
We welcome responsible disclosure of security vulnerabilities.
If you believe you have identified a security issue, please report it responsibly via:
Email: security@swazzy.co
Learn more about our Responsible Disclosure Policy.
Need More Information?
We understand that every customer has different security requirements. If you have specific questions or require additional assurance, our team is happy to help.
Contact us to discuss your security requirements