← Trust Center

Platform architecture

Platform architecture

SwiftCode is a clinical layer built on top of mature, enterprise-grade platforms. We focus our engineering on hospitals, staff, roles, and emergency workflows — and delegate security-critical infrastructure like identity and cloud hosting to established providers, rather than reinventing it.

Separation of responsibilities

SwiftCode is built as layers with clear ownership: SwiftCode ID sign-in is delegated to ZITADEL Cloud, while SwiftCode owns authorization and the clinical business logic. Together they deliver the healthcare communication platform.

Identity Layer— ZITADEL Cloud (current) → WorkOS (future)

Authentication · Single Sign-On · Multi-Factor Authentication · Passkeys · Identity Federation

Application Layer— Owned by SwiftCode

Authorization · Hospitals · Facilities · Staff · Roles & Permissions · Clinical Workflows

Healthcare Communication Platform

Incidents · Alerts · Messaging · Operations

Identity: ZITADEL now, WorkOS future Owned by SwiftCode Capabilities
SwiftCode is built on a layered architecture that separates identity management from healthcare business logic. SwiftCode ID authentication is delegated to ZITADEL Cloud, while SwiftCode remains the authoritative source for authorization, clinical workflows, and healthcare operations. This separation improves security, simplifies compliance, and allows us to leverage trusted enterprise technologies without compromising control over patient care workflows.

How it connects to trusted platforms

The same architecture from an infrastructure view: clinical staff use SwiftCode across four surfaces, while identity, cloud, and (planned) messaging are handled by dedicated platforms.

  • SwiftCode Platform — Hospitals, facilities, staff, roles, permissions, authorization, clinical workflows, and emergency codes.
  • Clinical Communication (in-house) — Incidents, alerts, secure messaging, clinical notes, QR verification, and the audit trail — built and owned by SwiftCode, with AES field-level message encryption.
  • Identity Platform — Authentication, MFA, passkeys, enterprise SSO, and federation. ZITADEL Cloud today; WorkOS is the planned future direction.
  • Amazon Web Services — Cloud foundation — availability, encryption, backups, and disaster recovery.
SwiftCode (built in-house, incl. messaging) Identity platform (ZITADEL now, WorkOS future) Cloud foundation

Built on trusted technologies

SwiftCode intentionally builds on mature, enterprise-grade platforms instead of recreating security-sensitive infrastructure. This keeps critical controls in the hands of specialists whose entire business is getting them right.

Identity

SwiftCode ID sign-in is delegated to ZITADEL Cloud today, and the legacy password path is being retired as staff migrate. WorkOS is the planned future identity platform; the migration path is documented and ZITADEL remains in production until then.

ZITADEL provides

  • Single sign-on (SSO)
  • Multi-factor authentication (MFA)
  • Passkeys / WebAuthn
  • OpenID Connect (OIDC) and OAuth 2.0
  • Enterprise identity federation

SwiftCode owns

SwiftCode resolves roles, permissions, and facility scope itself — so identity and authorization stay cleanly separated regardless of the identity provider.

Messaging

Secure clinical messaging is built and owned in-house by SwiftCode — because it is PHI-aware, integrates with incidents and clinical notes, and must be encrypted and audited.

SwiftCode provides

  • PHI-aware secure messaging
  • AES field-level message encryption
  • Audit logging + retention/disposal
  • Incident & clinical-note integration
  • Delivery/read receipts and presence (roadmap)

SwiftCode owns

SwiftCode owns the full messaging path: PHI minimization, AES field-level encryption of message bodies, retention/disposal, and audit logging — tied directly into incident and clinical workflows.

Cloud infrastructure

SwiftCode is deployed on Amazon Web Services.

AWS provides

  • High availability
  • Scalability
  • Encryption
  • Automated backups
  • Disaster recovery
  • Continuous monitoring

SwiftCode owns

Infrastructure is defined as code and continuously monitored, so environments are reproducible and changes are reviewable.

SwiftCode ID credentials are held by ZITADEL Cloud, not SwiftCode. Passwords, MFA, and passkeys for SwiftCode ID are held and verified by ZITADEL; SwiftCode receives a standards-based identity token — never those credentials — and resolves what each user may do from their SwiftCode role. We are retiring the legacy password sign-in path as staff move to SwiftCode ID.

Compliance at the identity layer

Because SwiftCode ID sign-in is delegated to ZITADEL Cloud, the identity layer runs on a service that ZITADEL independently certifies and operates as a data processor — so credentials, MFA, and passkeys sit behind an audited, standards-based platform.

ZITADEL Cloud certifications

Maintained and attested by ZITADEL for the identity service.

ISO 27001 CertifiedSOC 2 Type IIGDPR (Data Processor)HIPAA (BAA available)OpenID CertifiedEU-U.S. / UK / Swiss Data Privacy Framework

Data residency

Identity data can be pinned to Switzerland, the European Union, or Global regions.

Data processing

A Data Processing Agreement is available with standard contractual clauses, technical & organizational measures, and a published sub-processor list.

What this does — and doesn't — mean. The certifications above are ZITADEL Cloud's own, covering the identity service SwiftCode relies on; they are verifiable at zitadel.com/gdpr. They strengthen the identity layer, but they do notcertify SwiftCode itself. SwiftCode is not HIPAA-, SOC 2-, or ISO 27001-certified, and does not claim to be.

Designed for healthcare

A clear, honest view of what "HIPAA" means for software — and how SwiftCode is built with the HIPAA Security Rule in mind.

There is no official HIPAA certification for software. HIPAA compliance depends on how systems are designed, deployed, configured, and operated — it is a property of an organization and its environment, not a badge a product can earn. SwiftCode is built with healthcare security principles in mind by leveraging trusted technologies and operational best practices; we do not claim to be HIPAA-certified, and we make no legal guarantees.

The security measures our design centers on include the following. Field-level encryption of message bodies and clinical notes is live today; some infrastructure controls (network TLS termination and database-level encryption at rest) are defined in our infrastructure-as-code and pending final production cutover — see Healthcare readiness for live status.

  • Field-level encryption of message bodies and clinical notes (AES-256-GCM)
  • Encryption in transit (TLS) and database-level encryption at rest
  • Centralized identity management
  • Audit logging of security-relevant actions
  • Least-privilege, role-based access control
  • Continuous monitoring
  • Disaster recovery and backup strategies
  • Infrastructure as code

Compliance is a shared, organizational effort

Even with strong technical controls, HIPAA compliance also requires work that lives with the healthcare organization and its operating environment:

  • Organizational policies
  • Administrative safeguards
  • Workforce training
  • Risk assessments
  • Business Associate Agreements (BAAs), where applicable

For an honest view of our current maturity and HIPAA Security Rule alignment, see Healthcare readiness.

Security principles

The commitments behind the architecture, at a glance.

Authentication managed by ZITADEL (WorkOS planned)
Secure clinical messaging built in-house
Hosted on Amazon Web Services
Encryption by default
Least-privilege architecture
Security-first engineering

Evaluating SwiftCode for your facility?

Enterprise customers may request our security questionnaire, architecture overview, and pilot materials during procurement — under NDA where required.

Security questions? security@swiftcode.tech