Third Party Index

Snapshot 30037

Document
Security page
URL
https://www.swivl.com/wp-content/uploads/2023/08/Security-Overview.pdf
Fetched
HTTP status
200
Content type
application/pdf
Fetch mode
pdf
Size
1348633 bytes
SHA-256 (raw)
27cf340a84704265665a040538bc1095a6d4e01e64b2b51688f7c8e7c2cac25f
SHA-256 (normalized text)
dff476e8ad70c2688dc3c06ecf85196204f84509e0765bd68c5d730fe4f8968e

Normalized text

Scripts and page chrome removed; this is what change detection compares.

        Security Overview
                           We always welcome a conversation so we can explain what we do and
                           why we do it. We are happy to review and sign additional security and
                           privacy contracts as required. At the end of the day, the most important
                           thing to me and Swivl, is to protect your kids like we protect our own.

                           -Vladimir Tetelbaum, co-Founder and CTO

        Swivl set out to build a secure platform for educators to use video for collaboration, growth,
        and impact. Our only business model involves delivering the best in class solutions and at a
        reasonable cost. We do NOT subsidize with ad revenue or customer data mining. With over
        50,000 schools and universities using Swivl products, we understand the sensitive nature of
        the video content we safeguard. We focus on how to make collaboration work seamlessly while
        making sure that the videos are seen only by the intended viewers.
        Infrastructure
        Swivl is built on top of Amazon AWS Cloud platform. This is a partial list of assurance programs
        with which AWS complies: SOC 1/ISAE 3402, SOC 2, SOC 3 FISMA, DIACAP, and FedRAMP PCI
        DSS Level 1 ISO 9001, ISO 27001, ISO 27017, ISO 27018.

        Swivl uses AES-256 encryption for data storage and TLS 1.2 for data transfer. Databases are
        regularly backed up and encrypted. We use a number of tools for intrusion monitoring and
        vulnerability testing. Processes are in place for continual security review, monitoring, and
        improvement. Swivl Team content can be stored in United States, Canada, European Union,
        Singapore, or Australia.

        Policies
        We have a number of internal and customer policies to ensure we meet our customer’s security
        and privacy needs. These are regularly reviewed and updated with the latest requirements and
        industry standards. Internally we have severely limited access to customer data, robust
        password and 2FA requirements, coding and review practices, and VPN and firewall
        requirements. For our customers, we control data access, ownership, and viewership; video
        retention and deletion; activity notifications; and a number of administrative tools. View our
        latest Reflectivity privacy policy and MirrorTalk privacy policy.
        Compliance
        We are committed to align with the needs and requirements of various
        institutions. On a regular basis we undergo extensive security surveys,
        reviews, and conduct conversations with stakeholders. We can review and
        accept additional requirements where they are not in conflict with our
        mission, goals, and make sense for the business. From day one, we have
        aligned our privacy policy and terms with the latest industry standards and
        requirements. In addition to FERPA, COPPA, and joining the Privacy Pledge
        in the U.S., we are also aligned with European GDPR requirements.

www.swivl.com | 1-888-837-6209