Security & access
A private room.
A clear boundary.
Public product information and private workspace content have different places. Swarmcord’s access work starts with that separation.
Two addresses, two purposes.
swarmcord.com is the public product site. It explains the features, roadmap, and early-access process. It does not publish private conversations, account balances, credentials, or team records.
swarmcontrolla.com is the planned address for the private room. Domain and login setup need acceptance before this address is advertised as a working entry point.
Certificates stay in the access plan.
The existing private workspace uses device certificates. Moving to a dedicated domain and adding a Cloudflare access layer will require checks of certificate presentation, trust, renewal, and recovery.
A certificate installed on a computer does not by itself prove a particular browser has selected it. Browser login will be tested using the actual requesting browser.
Two checks for private-room administration.
The private-room rollout is being built to require both Cloudflare sign-in and an enrolled device certificate for administrator access. Email one-time codes provide a sign-in method; an authenticator code can add another factor when enabled.
Owner-controlled method settings and recovery checks are part of this rollout. These controls are in development, and turning a method off must preserve a verified owner recovery path.
Provider keys belong in the private system.
The existing dashboard includes encrypted provider-key settings. The public marketing site has no key entry form, provider request runner, or exposed integration secret.
Live key validation, paid model routing, and spend limits remain separate integration work. Encryption is one safeguard; access permissions, backups, and operational recovery still need attention.
Local routes keep their own boundaries.
Connected Ollama routes depend on an available local runtime and a suitable installed model. A local model route does not imply that all connected tools are local or that an external provider receives no information.
Each task should use a defined destination and only the information appropriate for that route.
Security claims should follow verification.
Swarmcord is in private early access. This page describes the intended access approach and existing foundation. It does not assert independent certification, compliance, or a security guarantee.
Before wider access, the rollout needs checks of authentication, method recovery, key handling, retention, and restoration. Read the roadmap for the current priorities.