New research: the Runtime Identity Security category, defined. See how Whiteswan closes the gap →
Contact Book a demo Start a pilot
Start a pilot

Home / Trust & Security

Trust & Security

How We Secure the Platform You Trust With Every Identity.

Whiteswan sits in line with every privileged access decision your organization makes. That's a position we don't take lightly: here's how we secure our own platform, and what that means for your data.

Standards We Align To

Built to the Standards That Matter, From Day One.

KuppingerCole Rising Star, October 2025ISO 27001 (aligned to)SOC 2 Type II (aligned to)GDPR & HIPAA (aligned to)Okta · Microsoft · AWS integrations

These reflect the standards our controls are designed and tested against, not formal third-party certifications. We’ll update this page the day that changes.

Platform Security

How We Protect Your Data.

01

Encryption in Transit and at Rest

Policy decisions, audit logs, and credentials are encrypted end to end, with keys managed separately from the data they protect.

02

Zero Standing Access, Internally Too

Whiteswan engineers hold no standing access to customer environments. Support access is JIT-elevated, scoped, and logged like every decision our platform makes for you.

03

Controls Tested Against Recognized Standards

Our controls are designed and internally tested against SOC 2 Type II and ISO 27001 criteria, as part of an ongoing security program, not yet claimed as independent certification.

04

Resilient Infrastructure

Multi-region deployment with automated failover, so decision-engine availability doesn't become the thing standing between your users and access.

05

Continuous Monitoring

Our own infrastructure runs under the same in-line, continuous monitoring philosophy we build for customers, not periodic review, runtime visibility.

06

Responsible Disclosure

We work with independent security researchers under a coordinated disclosure policy. Report a concern through your account team or security@whiteswansecurity.com.

Your Data

Governed the Way We’d Govern Our Own.

Whiteswan processes access decisions and audit metadata, not the underlying application data those systems hold. Data residency, retention, and deletion terms are defined in your master agreement, and enforced the same way our platform enforces every other policy: at runtime, not on request.

Questions for Our Security Team?

Talk to Us Before You Trust Us.

Reach our security team directly with any question about how we protect your data.