Security
Local-first processing, on-device PII masking, and encryption at every layer. Sensitive operations run in a separate secure process that the user interface cannot access.
Data protection
Sensitive content is flagged and masked locally before reaching any AI provider. Policy state and plugin validation are encrypted at rest using the OS keychain.
A local ML model flags sensitive content before it reaches any AI provider. Three-layer detection: 500+ regex patterns, entropy analysis, and Piiranha ML classification. Runs entirely on the device.
PII is detected and masked before any data leaves the device. The transform proxy intercepts all LLM API calls, applies masking, verifies policy compliance, and audit-logs the request before forwarding.
Local model training is off by default. Activation requires explicit user consent with EULA acceptance. No silent enrolment. No data sent to third-party AI services for training purposes.
Policies define which AI providers and models users can access. Everything outside the allowlist is blocked at the application level. Per-group targeting for different teams.
Architecture
The user interface and the security layer run as independent processes. Data masking, encryption, policy enforcement, and tool routing all happen in the secure process. Even if the application has a vulnerability, protected data stays protected.
Access control
Every agent and every session is individually scoped. No shared credentials. No shared sessions. Revocation is granular.
Each agent authenticates with a token that binds identity, role, repository, and remit. Governance rules define boundaries. Agents check remit before acting and escalate when outside their domain.
Sessions are scoped per device. Revoking one device does not affect others. Brute-force protection on all authentication endpoints.
SAML 2.0, OIDC, Google, and Microsoft. Enterprise controls activate before the workspace loads. Authentication, policy fetch, and legal acceptance must all pass before any AI tools become available.
Encryption
The outcome
Compliance
Data stored in Zurich, Switzerland. Compliant with Swiss data protection law (FADP) and the EU GDPR. Full audit trails structured for SOC 2 and ISO 27001 reporting.
The EU AI Act requires human oversight, immutable audit trails, decision-point logging, and persistent identity management. Swarmix's structured conversations, proposal voting, plan gates, and agent identity system map directly to these requirements.
We are happy to walk the security team through the architecture, encryption model, and compliance posture.
A walkthrough of unified visibility, governance, and intelligence across every AI vendor and team.