Security Policy

Purpose and Scope

This document describes the security controls Swift-E Recording Services LLC applies to the Swift-E electronic recording platform. It is intended for clients and prospective clients conducting vendor security review, particularly title agents, lenders, and law firms with their own regulatory obligations.

It covers the Swift-E platform and the infrastructure that supports it. It does not cover County Clerk systems, which are operated by government agencies outside our control, or client-side environments. This document is informational and does not modify the Swift-E Terms of Service, Privacy Policy, or Refund Policy.

Platform and Hosting

Encryption

Customer Authentication and Account Security

Internal Access Control

Secrets Management

Payment Security

Document Handling and Subprocessors

Documents submitted for recording are stored in Azure Blob Storage and transmitted to the destination County in the format that County requires. Where a client uses the optional automated extraction feature, document content is processed by Microsoft AI services operating within Swift-E’s own Azure tenant.

Document content is not sent to any public or consumer AI service, and is not used to train any model.

Subprocessor Purpose Data Received
Microsoft Azure 

Hosting, database, blob storage, secrets 

management

All platform data

Azure AI Document 

Intelligence

Optical character recognition for optional extractionDocument images

Azure OpenAI Service 

(Swift-E tenant)

Structured field extraction for client reviewDocument text
Stripe, Inc. Payment processingPayment credentials, transaction data
Email delivery provider [INSERT]Transactional emailEmail address, message content
Extraction output is presented to the client for review and correction. No extracted value is transmitted to a County without human review.

Application Security and Change Management

Logging and Monitoring

Data Retention and Deletion

Data retention policies are currently under active development. Automated retention, deletion, pruning, and expiry processes for submitted documents, derived image files, extracted index data, session records, and logs have not yet been implemented or verified. Retention periods will be published once the retention system is fully implemented and validated.

Backup and Business Continuity

Backup and disaster recovery procedures are currently under review and implementation. Database backup method, backup frequency, retention period, geo-redundancy, blob storage replication, restore testing, Recovery Point Objective (RPO), and Recovery Time Objective (RTO) have not yet been finalized or verified. These details will be documented once the backup and business continuity processes have been fully configured and tested.

Incident Response and Breach Notification

Swift-E maintains an incident response process covering detection, containment, investigation, remediation, and notification. [CONFIRM — if no written plan exists, write a short one before making this statement. A two-page plan naming who does what is sufficient and is far better than an unsupported claim.]

Personnel and Contractors

Compliance Posture

We state our position plainly rather than implying certifications we do not hold.

Shared Responsibility

Security depends on both parties. Clients are responsible for:

Reporting a Vulnerability

If you believe you have found a security vulnerability in the Swift-E platform, report it to security@swifterecordingservices. Please include enough detail to reproduce the issue. We ask that you allow us a reasonable period to remediate before public disclosure, and that you do not access, modify, or delete data belonging to others, or degrade the service, while investigating. We will acknowledge reports promptly and will not pursue action against good-faith researchers who follow these guidelines.

Requesting Further Documentation

Clients and prospective clients conducting vendor review may request a completed security questionnaire, a written service provider or confidentiality agreement, or additional detail about a specific control. Contact customersupport@swifterecordingservices.com . Detailed architectural and configuration information is provided under a mutual non-disclosure agreement.