Security at Swift Fox
This page states what we actually do with the things ISPs trust us with, specifically enough for a vendor review to cite. If your due-diligence process needs more than what's here, email us and we'll answer directly.
Your customers' card data
Full card numbers never touch Swift Fox servers. Customers enter card details into an embedded form served by Spreedly, a PCI DSS Level 1 certified vault; what Swift Fox stores is a token. Recurring billing, refunds, and portal payments all run against tokens, and the vault is portable across 150+ merchant providers — your card data isn't locked to us or to any single processor.
Access to your network
Swift Fox is out-of-band by design: customer traffic never flows through our systems, so we can't become an outage. Monitoring runs through a pingbox, either on your network or hosted in our cloud, and in both cases the connection is initiated outbound from your side. There are no inbound ports to open and no firewall exceptions.
An on-site pingbox (a VM, a Raspberry Pi, or an embedded device) makes a single outbound TLS connection to our cloud, authenticated with a per-device client certificate, with no VPN involved.
A cloud pingbox runs in a dedicated container behind its own VRF on our tunnel concentrator. Your router builds the tunnel outbound to it, using the tunnel type and encryption settings you choose, and the container is firewalled to reach only Swift Fox and your network. Its default route is your router, so it has no other path to the internet. This is what makes one-paste onboarding possible: copy a config into your core router and monitoring starts in minutes.
Everything that reaches your gear — monitoring, config backups, the browser SSH terminal — travels through the pingbox. If Swift Fox is ever unreachable, your network keeps running without it.
Your data
Swift Fox is multi-tenant with per-ISP isolation: each ISP's operational data lives in its own database, and time-series metrics are scoped with per-ISP row-level policies. All traffic between your browser, your customers' portal, your pingbox, and Swift Fox is encrypted in transit.
Our staff
Multi-factor authentication is enforced on every Swift Fox staff account.
Questions and reports
Found a vulnerability, or working through a security questionnaire? Email [email protected] — it goes to our engineers, and we'd rather hear about a problem than not.