Security
We take security seriously. Learn about our security measures designed to protect dealer and customer data, and about the controls we are strengthening as part of our SOC 2 and ISO 27001 programmes.
Infrastructure Security
ToolSwift is entirely cloud hosted. We operate no on-premise infrastructure. Workloads are distributed across specialised providers, each used for what it does best.
Hosting Architecture
- Backend application compute and the production MongoDB database: Hetzner Cloud (Nuremberg, Germany)
- Encrypted backups: Hetzner Storage Box (Germany), held separately from the application host
- Frontend applications: Vercel's distributed edge network
- Object storage, secrets management, and transactional email: Amazon Web Services (S3, Secrets Manager, SES)
Network & Host Controls
- Host-based firewall and reverse proxy on production hosts
- Network-level DDoS mitigation provided by our infrastructure providers
- Restricted network exposure of database services behind firewall controls
- Blue/green deployment slots for zero-downtime releases and immediate rollback
A cloud-level firewall, application WAF with managed rule sets, and API rate limiting are being deployed under our current remediation plan. Relocating backend compute and database hosting to a US region is feasible if data residency requires it.
Data Encryption
Sensitive operations are handled server-side. Credentials, integration keys, and privileged operations are never exposed to client-side code, and frontend applications hold no secrets.
Password Security
- Passwords are hashed using bcrypt and never stored in recoverable form
- One-time passcode verification is available for customer authentication flows
In Transit
- All public application traffic is served over HTTPS/TLS
- Traffic to our infrastructure and storage providers is encrypted in transit
At Rest
- Backups are held in an encrypted repository
- Encryption of live database storage at rest and TLS on database connections are scheduled work in our current remediation plan
Access Controls
Access to production infrastructure and data is deliberately restricted to a small number of named individuals.
- Only two members of staff hold access to production infrastructure and data
- Server access is restricted to SSH key-based authentication; password authentication is disabled
- Database administrator accounts are attributable to named individuals
- Customer account passwords are hashed with bcrypt; OTP verification is available for customer authentication flows
- Multi-tenant data is scoped by store at the application layer so one dealer cannot access another dealer's records
In our current release and remediation pipeline: per-user identity replacing shared logins, granular role-based permissions across application endpoints, an append-only activity log with attribution, multi-factor authentication on infrastructure provider accounts, and quarterly privileged access reviews.
Monitoring & Change Management
Production application and infrastructure logs are centrally collected. Changes follow a documented engineering process before they reach production.
Monitoring
- Centralised logging with Grafana, Loki, and Vector
- Application error monitoring through Sentry on the customer portal, with backend and administrative dashboard coverage scheduled
- Support issues are triaged in our issue tracker and remediated through the same specification, review, and deployment process
- Threshold alerting for CPU, memory, disk, and endpoint availability is scheduled in our current remediation plan
Change Process
- Written specification produced and approved before development
- Work completed on a feature branch
- Every change reviewed through a pull request before merge
- Deployment uses blue/green application slots allowing immediate rollback
- Customer-facing changes are communicated by email to store administrators from noreply@toolswift.ca, with in-app notices for new feature releases
Incident Response & Availability
We maintain procedures to identify, contain, and remediate security and operational incidents, and we are formalising incident management under our SOC 2 programme.
- Critical defects and incidents: target response within 24 hours
- Standard change and support requests: fulfilled within one to three business days
- Published availability target of 99.9%, with blue/green deployment for zero-downtime releases and immediate rollback
- Automated encrypted backups with restore verification, independent of the application host
- A second production node with health-checked load balancing and tested failover is on our roadmap
Security Programme
We are building independent verification behind our controls rather than relying on our own assurance alone.
- SOC 2 programme in progress (Security, Availability, Confidentiality)
- ISO 27001:2022 being pursued in parallel
- Internal infrastructure and control readiness assessment completed 4 September 2026, with a prioritised remediation plan in execution
- Codebase audit before each major feature release
- Third-party penetration test planned ahead of the SOC 2 observation period