generated: '2026-07-21' method: searched source: https://www.swap-commerce.com/security-compliance docs: https://www.swap-commerce.com/security-compliance standards: - id: iso-27001-2022 conforms: true evidence: >- SWAP Commerce holds ISO 27001:2022 certification, issued by an accredited third-party auditor, maintained through ongoing surveillance audits and annual reviews. source: https://www.swap-commerce.com/security-compliance - id: soc2-type2 conforms: false status: in-progress evidence: >- "We are working toward SOC 2 Type 2 certification and follow the Trust Services Criteria for security, availability, and confidentiality." Architecture designed to meet SOC 2 data-isolation requirements. source: https://www.swap-commerce.com/security-compliance - id: gdpr conforms: true evidence: SWAP Commerce complies with the EU General Data Protection Regulation (GDPR). source: https://www.swap-commerce.com/security-compliance - id: ccpa conforms: true evidence: Complies with the California Consumer Privacy Act (CCPA). source: https://www.swap-commerce.com/security-compliance - id: oauth2 conforms: false evidence: Key-auth platform; no OAuth2/OIDC security schemes documented. - id: rfc9457-problem-details conforms: false evidence: >- Errors are HTTP-status-driven with a compact statusCode/message/error JSON body (NestJS-style), not application/problem+json. - id: tls-1.2-plus conforms: true evidence: All data in transit over HTTPS with TLS 1.2 or higher enforced across endpoints. source: https://www.swap-commerce.com/security-compliance security_program: penetration_testing: Annual third-party penetration testing and vulnerability assessments. encryption_at_rest: GCP KMS-managed keys. encryption_in_transit: HTTPS / TLS 1.2+. infrastructure: Google Cloud Platform (GCP); single-tenant and multi-tenant isolation models.