Compliance
We are building a formal compliance programme with independent verification. Learn about our SOC 2 and ISO 27001 work, payment security posture, and how we align with privacy regulations.
SOC 2
In ProcessActive programme with external consultant. Trust Services Categories: Security, Availability, Confidentiality
ISO 27001
In ProcessISO 27001:2022 pursued in parallel; Annex A scoped, SoA and policy set in development
SOC 2 (In Process)
ToolSwift is engaged in an active SOC 2 programme with an external compliance consultant. We do not yet hold a SOC 2 report.
Current Status:
- Internal infrastructure and control readiness assessment completed 4 September 2026
- Prioritised remediation plan with named owners is in execution
- Trust Services Categories in scope: Security, Availability, and Confidentiality
- Observation period start date will be set once remediation is verified and agreed with the CPA firm performing the examination
We are willing to share readiness status and the remediation plan under NDA, and to notify customers when the report is issued.
ISO 27001 (In Process)
ISO 27001:2022 is being pursued in parallel with SOC 2. The Annex A control set has been scoped. The Statement of Applicability, risk register, and policy set are in development. No certification body has been engaged yet.
Payment Card Security (PCI)
ToolSwift does not hold a PCI DSS certification in its own name and does not store cardholder data on its infrastructure. Card payments are processed by PCI DSS Level 1 certified providers. We can supply their Attestations of Compliance on request.
Policies & Risk Assessment
A full written information security policy suite is being drafted with our external compliance consultant, covering network security, data classification, access control, incident management, change management, data retention, acceptable use, and device security.
- Documented engineering practices are in force today: written specification before development, pull request review before merge, and no change to production without review
- A formal, scheduled risk assessment programme is being established under SOC 2 and ISO 27001, including a maintained risk register
- Most recent assessment: internal readiness review completed 4 September 2026
- A third-party penetration test is planned ahead of the SOC 2 observation period
Infrastructure & Vendor Assurance
We leverage certified infrastructure providers and retain their current attestations. A formal processor and vendor register with risk ratings and annual review is being built as part of our compliance work.
- Hetzner — ISO 27001 certified data centres
- Amazon Web Services — SOC 2 and ISO 27001
- Vercel — SOC 2
- Payment processors — PCI DSS Level 1
Physical security of data centres is provided by these providers. ToolSwift retains responsibility for server configuration, encryption, access control, monitoring, firewall rules, and backups within that environment.
Regulatory Awareness
We work to align with applicable laws and regulations in the jurisdictions where we operate, including data protection and privacy requirements.
- Data protection and privacy laws (GDPR, CCPA, PIPEDA)
- Industry and e-commerce regulatory requirements
- International data transfer and residency considerations
Questions About Compliance
If you have questions about our compliance practices or would like to discuss readiness materials under NDA, please contact us.
Contact: support@toolswift.ca