Security
Last updated: July 9, 2026
This page is a practical account of how Swift SOAP actually protects your data — what we collect, where it goes, and what we don't do with it. It's a companion to our Privacy Policy, which is the full legal version; this page is meant to answer the questions a practice evaluating us would actually ask.
Swift SOAP is an early-stage product. We haven't pursued formal certifications like SOC 2 or ISO 27001 yet — that's a real, ongoing compliance program, and it's not honest to imply we have one before we do. What follows is accurate today, and we'll keep it that way as it changes.
Encryption
All traffic between the app, our servers, and our infrastructure providers is encrypted in transit (HTTPS/TLS). Data at rest — your account, patient records, transcripts, and notes — is encrypted by our database and storage provider, Supabase.
How consultation audio is handled
Audio is processed to produce a transcript, a structured note, and diagnostic suggestions — then deleted from our servers immediately after processing completes, whether or not it succeeds. We never retain the original recording.
AI processing
Transcription and note generation run on Groq's infrastructure. Groq's terms commit that customer inputs and outputs are never used to train or fine-tune their models, and inference requests aren't retained by default — they're only briefly logged (up to 30 days) for abuse investigation or troubleshooting, the same as most infrastructure providers.
Diagnostic suggestions are grounded in a library of veterinary reference material we search at the time of the consultation — every suggestion cites the source it came from, rather than relying on the model's own unstated training knowledge.
Who we share data with
We don't sell data, and we don't have a marketing or analytics vendor sitting in the middle of your consultation data. The infrastructure providers that process data on our behalf, and what each one sees:
- Groq — transcribes audio and drafts notes and diagnostic suggestions
- Qdrant — powers the veterinary reference search behind diagnostic citations; receives clinical search terms only, never audio, transcripts, or owner names
- Supabase — authentication, database, and file storage
- Render — hosts our backend servers
- RevenueCat and its payment processor — manages subscriptions; we never receive or store your full card number
Account and data deletion
Deleting your account is a real, immediate action available directly from Settings in the app — not a support ticket. It permanently removes your patient records, consultation history, and exported PDFs, then deletes the account itself. Individual consultations can be deleted the same way without touching the rest of your account.
Questions for procurement or IT review
If your practice needs specific documentation we don't have listed here — a data processing agreement, a security questionnaire, or anything else — email us and we'll work through it directly. Formal certifications are on our roadmap as we grow; we'd rather tell you honestly where we stand today than make you guess.
Contact
Questions about how we handle data? Email us at hello@swiftsoap.com.