Trust & security

Where your data lives, how we decide what reaches you, and how to ask us the rest.

Where Your Data Lives

SWIX’s own data centre, in New Zealand

SWIX owns and operates its own data centre here in New Zealand. It isn’t resold space in someone else’s cloud — we don’t rent capacity in Sydney or Virginia, and we don’t hand your telemetry to an offshore platform. Everything SWIX collects about your business is stored, processed and backed up on New Zealand soil, under New Zealand law.

What Leaves The Country

What, if anything, touches an offshore service

Our aim is that nothing does. If any third-party service touches customer data — email or SMS alert delivery, for instance — we’ll say precisely what stays onshore and what doesn’t, rather than let the New Zealand claim stand unqualified.

The Detail

Ask us the hard questions

We’d rather walk you through the specifics than summarise them in a line. On a call we’ll cover, in as much depth as you need:

  • The agent — what it collects from your devices, and what it doesn’t.
  • Microsoft 365 & Google Workspace — exactly what we ingest from your cloud accounts.
  • Retention and access — how long data is kept, and who at SWIX can see it.
  • Encryption, sub-processors and incident handling — how your data is protected and what happens if something goes wrong.
  • Contract terms — commitment, notice, and what happens to your data if you leave.

Vulnerability Disclosure

Found a problem? Tell us

Report a security vulnerability to hello@swix.co.nz, or see our machine-readable disclosure policy at /.well-known/security.txt.

Read the full data & privacy policy.

Alert Triage

How we decide what’s worth telling you

Every event SWIX sees is scored on a severity scale from 0 to 15. This is what keeps your inbox free of noise: most events sit at the bottom of the scale and are resolved automatically, with nobody paged and nothing sent to you.

  • Levels 0–5 — routine. Non-security noise, authorised activity, or low-impact errors. Logged, not escalated.
  • Levels 6–9 — worth a look. Low-threat items, first-time occurrences, or requests from unrecognised sources.
  • Level 10 and above — a human is notified. Repeated failed logins, signs of tampering, or patterns consistent with a targeted attack. This is the threshold where our security team is alerted directly, and where a customer notification can follow.
  • Level 15 — severe. Immediate intervention, no waiting for a scheduled review.

The scale exists so a person, not an algorithm alone, makes the call on what reaches you — and so what does reach you is explained in plain English, not left as a raw log entry.

Still have questions?

Talk to us directly — we’d rather answer a hard question before you sign up than after. Call 07 929 2200 or email hello@swix.co.nz.