Skip to main content
SwiftCase
PlatformForward-deployedSwitchboardFeaturesSolutionsCase StudiesFree ToolsPricingAbout
Book a Discovery Call
SwiftCase

Workflow automation for UK service businesses. Created in the UK.

A Livepoint Solution

Platform

  • Platform Overview
  • Workflow Engine
  • Case Management
  • CRM
  • Document Generation
  • Document Extraction
  • Context Graph
  • Data Model
  • Integrations
  • Analytics

Switchboard

  • Switchboard Overview
  • Voice AI
  • Chat
  • Email
  • SMS
  • WhatsApp

Features

  • All Features
  • Claims Operations
  • High-Volume Operations
  • Multi-Party Collaboration
  • Contract Renewals
  • Compliance & Audit
  • Pricing
  • Case Studies
  • Customers
  • Why SwiftCase

Company

  • About
  • What is SwiftCase
  • Our Team
  • Adam Sykes
  • Nik Ellis
  • Implementation
  • 30-Day Pilot
  • Operations Pressure Map
  • For Your Role
  • Peer Clusters
  • Engineering
  • Careers
  • Partners
  • Press
  • Research
  • Tech Radar
  • Blog
  • Contact
  • SwiftCase Signal

Resources

  • Use Cases
  • Software
  • ROI Calculator
  • Pressure Diagnostic
  • Pilot Scope Estimator
  • Board Case Builder
  • Free Tools
  • Guides & Templates
  • FAQ
  • Compare
  • Best Practices
  • Changelog
  • Documentation
  • Help Centre

Legal

  • Privacy
  • Terms
  • Cookies
  • Accessibility

Stay in the loop

Cyber Essentials CertifiedGDPR CompliantUK Data Centres

© 2026 SwiftCase. All rights reserved.

Platform

Securityyoucanprove.
Notjustclaim.

Cyber Essentials certified. UK data centres only. Quarterly penetration testing. Your data stays where it should, under your control and protected by real security measures.

Talk to Us About Security
See Platform

Certifications

Credentials that matter.

We don't just say we're secure. We prove it with recognised certifications.

Certified

Cyber Essentials Certified

Government-backed certification for cyber security. Passed, not pending. We meet the baseline for protecting against common cyber attacks.

Compliant

GDPR Compliant

Built for UK and EU data protection requirements. Data processing agreements, subject access requests, and right to deletion built in.

Data Protection

How we protect your data.

UK Data Residency

Your data stays in the UK. Not routed through servers abroad. Not stored in jurisdictions with different data laws. UK data centres only.

Encryption at Rest

All data encrypted when stored. AES-256 encryption. Even if someone accessed the physical storage, your data would be unreadable.

Encryption in Transit

TLS 1.2+ for all connections. Your data is encrypted between your browser and our servers. No exceptions.

Role-Based Access

Control who sees what. Granular permissions by role, team, or individual. Users only access what they need.

Audit Logging

154+ event types logged. Every login, every change, every access. Full trail of who did what and when. Exportable for compliance.

API Security

API keys with granular permissions. Rate limiting. IP allowlisting available. Secure integration without exposing your system.

Read more about UK data sovereignty

Access Control

Control who accesses what.

Granular permissions. Multi-factor authentication. IP restrictions. You decide who gets in.

Two-Factor Authentication

Optional 2FA for all users. TOTP-based. Add an extra layer of security to every login.

IP Restrictions

Restrict access by IP address or range. Lock down access to your office network if required.

Session Management

Automatic session timeout. Force logout across devices. See active sessions and revoke access.

Data Isolation

Each customer's data is logically isolated. No cross-tenant data access. Your data is yours alone.

Least privilege in practice

Five checks stand between a user and a case.

“Granular permissions” is what every vendor says. Here is the actual mechanism, in the order it runs, so you can judge whether it covers the confidentiality your operation has to hold. Each layer can deny on its own.

Role

What this person can do at all

Roles bundle capabilities, from standard user through team leader to internal admin, alongside granular roles for specific powers such as managing file tags or approving permission requests. A role is granted by a named administrator and the grant is logged.

Workflow

Which processes they see

Visibility is set per team member, per workflow, and down to individual statuses within a workflow. Someone handling intake can be shown the first three stages of a process and nothing beyond them.

Product

Whether this task type is restricted

A task type can be marked restricted, which means holding a role is no longer enough. Access then depends on having an active assignment on the case itself. Allow rules form a whitelist by case relationship, and a deny rule always wins over an allow.

Case

Who they are on this particular case

Case relationships decide what a person sees on the case in front of them. The same user can be case owner on one, an expert on another, and hold no relationship at all to a third, which is what makes note and form visibility workable without maintaining lists by hand.

Field

What renders once they are in

Forms, actions and notes each declare which user types can see them, and visibility rules can hide content until named questions are answered. Files carry their own permissions, separate from the documents they relate to.

Hidden and forbidden are separate

A restricted task type can also be kept out of listings entirely, configured independently of who may open it. Cases that should not advertise their existence do not appear in a count, a search result or a report for anyone without access.

Asking for access is part of the record

Users request a role rather than being handed one informally. The request sits pending until a permissions manager grants or denies it, and the request, the decision and the person who made it are all recorded for the access review you will eventually be asked for.

Audit Trail

154+ event types. Full history.

Every action logged. Every change recorded. When auditors ask what happened, you have the answer. Exportable reports for compliance reviews.

User login and logout
Password changes
Permission changes
Record creation and updates
Document generation
Email sends
API calls
Workflow executions
File uploads and downloads
Data exports
Configuration changes
Integration activity
Audit Log
14:32:01
Updated case CLM-2024-001
Sarah M.
14:31:45
Generated settlement_letter.pdf
System
14:30:22
Logged in from 192.168.1.100
Sarah M.
14:28:15
Exported contacts report
James K.
14:25:00
Workflow 'Case Closure' executed
System

Our security commitment.

What we promise you.

No data selling

Your data is yours. We don't sell it, share it, or use it for anything except running your system.

Transparent incidents

If something goes wrong, you'll know. We disclose security incidents promptly and clearly.

Regular testing

Ongoing security assessments. We don't set and forget. We continuously improve.

UK-based support

Security questions answered by real people in the UK. Not outsourced, not scripted.

Data Processing

Where your data lives. Who touches it.

Full transparency on data processing, sub-processors, and data flows. Everything your DPO needs to complete a vendor assessment.

Data Processing Agreement

We provide a comprehensive DPA covering GDPR Article 28 requirements. Includes data processing purposes, categories of data subjects, security measures, and sub-processor obligations.

Available on request before contract signing

Sub-Processors

We use a limited number of sub-processors, all UK or EU-based. Our primary infrastructure runs on UK data centres. We notify customers before adding any new sub-processor.

Current sub-processor list available on request

Data Retention & Deletion

Configurable data retention policies per workflow. Automated deletion schedules. Complete data export in standard formats. Full deletion on contract termination with certificate of destruction.

Retention periods configurable per case type

Data Portability

Export your data at any time in CSV, JSON, or XML formats. No vendor lock-in. Your data is yours and you can take it with you.

Self-service export available in all tiers

Compliance Journey

Continuous improvement, not checkbox compliance.

2021

Cyber Essentials

Achieved Cyber Essentials certification, the UK government-backed scheme for cyber security. Renewed annually since.

2018

GDPR Readiness

Full GDPR compliance programme including DPA templates, DSAR handling, and data protection impact assessments.

Security questionnaire

Need to complete a vendor security assessment? We can provide pre-completed responses to standard security questionnaires including CAIQ, SIG, and bespoke formats.

  • Pre-completed CAIQ responses
  • SIG Lite and SIG Full available
  • Bespoke questionnaire turnaround within 5 business days
  • Penetration test summary available under NDA
Request Security Documentation

Common questions we answer

Where is data stored?
UK data centres only. No data leaves the UK.
Is data encrypted?
AES-256 at rest, TLS 1.2+ in transit.
Do you have a DPA?
Yes, GDPR Article 28 compliant. Available pre-contract.
Penetration testing?
Annual third-party pen tests. Summary available under NDA.
Business continuity?
Automated backups, disaster recovery, 99.9% uptime SLA.

Questions about security?

We're happy to discuss our security measures, provide documentation for your compliance team, or answer specific questions about how we protect your data.

Contact Security Team
Explore Platform