(Trust Center)Security & Architecture

Learning doesn't start with training. It starts with safety.

SwarmMind is designed to give people a safe space to think, reflect, learn and share — without losing control of their own learning.

Version: 0.11 (Pilot)Date: 19 Aug 2026Provider: Intunex Oy

More than a privacy policy

That requires more than a privacy policy. It requires clear data boundaries, strong tenant isolation, controlled AI access and an architecture where customer data is handled deliberately.

Built in FinlandPersistent customer data hosted in the EUPrimary AI processing in the EU
01

EU-first architecture

Your data stays yours.

  • EU-hosted customer data: SwarmMind's persistent customer data is hosted in Supabase's Stockholm region, Sweden.
  • EU-based primary AI processing: Primary generative AI processing, embeddings and speech transcription run on Scaleway infrastructure in Paris, France.
  • No model training by Intunex: Intunex does not use customer content to train or fine-tune AI models. Scaleway and the OpenAI API, when used as a backup, process content under their applicable API terms to provide the requested response rather than to train shared models. Other supporting providers and their roles are described separately in the Privacy Notice.
  • Transparent external processing: some supporting functions — such as public web search, page and document reading, and an AI backup — use named external providers. What each provider receives and the available customer controls are described in our Privacy Notice.
02

Tenant isolation by design

Built to prevent cross-organisation exposure.

  • Row-Level Security is enabled across all 127 production tables in the public database schema. A table without an explicitly allowing policy is closed to customer roles by default.
  • Server-side tenant checks: tenant-bound server functions validate the user's membership in the requested organisation. A CI invariant monitors the agreed coverage of these checks.
  • Purpose-scoped data access: agents receive context for a defined purpose and organisation. Elevated server paths do not rely on a user-supplied organisation identifier alone.
03

Agent boundaries and visible learning data

Safely multi-tenant.

  • Verified context: agents operate within a verified organisation and purpose context.
  • Visible learning data: information proposed for a user's Learning Identity remains visible and user-controlled. SwarmMind does not maintain a hidden learning profile behind the user.
  • Deliberate sharing: personal reflection is private by default. Sharing is a conscious user action; private content is not silently turned into organisational insight.
  • Auditable access: selected sensitive access and security events are recorded by source, scope and purpose without intentionally copying conversation or reflection content into the audit trail.
04

AI security safeguards

AI that knows its boundaries.

  • Prompt-injection detection: all eight user-facing conversational agent paths use a shared eight-pattern prompt-injection scanner. Detected patterns are logged and passed to the model as a security warning; the scanner is not described as preventing every attack.
  • Document handling: uploaded document content is separately sanitised using nine detection patterns and zero-width-character removal before use in supported AI context.
  • Trust-classified context: SwarmMind distinguishes between user input, organisational knowledge, user-provided sources, external content and uploaded documents when constructing AI context.
  • Safer public-web retrieval: Tavily search phrases are generated by SwarmMind, checked against twelve categories of direct identifiers and stopped when risky information remains. This control applies to the external search phrase, not to all AI conversations.
05

Encryption, audit and operational controls

Everything is verifiable.

  • Encryption in transit: verified application traffic uses HTTPS/TLS. The production PostgreSQL service has SSL enabled with TLS 1.2 as its minimum supported protocol.
  • Encryption at rest: Supabase states that database disks and backups are encrypted using AES-256 under its current service security architecture.
  • Integrity-verifiable audit trail: selected security-critical and administrative events are recorded in a hash-chained audit trail whose integrity can be checked. It is not described as tamper-proof or unalterable.
  • Operational safeguards: rate limits, tenant-boundary event logging, privilege-escalation event logging and selected product-quality alerts support abuse prevention and incident investigation.
06

Private means private

No silent access. No hidden review. No surprises.

Private content may be processed to provide the learning experience the user requests. Intunex does not use private reflection for model training, prompt tuning, hidden employee evaluation or unrelated product research.

Information proposed for the Learning Identity stays in the user's field of view. The user can review and manage what is stored and what is deliberately shared.

07

Incident response

Intunex maintains an escalation path for security and personal-data incidents. Affected customers are informed without undue delay in accordance with the applicable agreement and data-protection responsibilities.

The GDPR's 72-hour supervisory-authority deadline applies to the Controller. A separate 72-hour customer-notification promise is made only where agreed in the customer contract.

Want the full picture? We provide a detailed architecture brief for IT and security teams — request it here. No sales pitch, just facts.