● Legal
Security
How to reach us about a vulnerability, what this website runs on, and how to verify anything that claims to be a payment instruction from swelv.
Last updated 14 Aug 2026
Scope of this page
This page covers swelv.io, our public website. Security commitments for the swelv platform, including controls, subprocessors, and incident handling, are documented separately and shared under our agreement with your fund. Ask us and we will walk you through them.
Reporting a vulnerability
If you have found a security issue, tell us at info@swelv.io with enough detail to reproduce it: the URL, the steps, and what you were able to observe. A proof of concept helps. We will acknowledge your report and keep you updated while we work on it.
We are a small team and we read these ourselves. We do not currently run a paid bounty programme, and we will credit you if you would like us to.
What we ask of researchers
While you are testing, please:
- stay on swelv.io, and do not test the platform, customer environments, or any fund data;
- do not run attacks that degrade the site for other people, such as denial of service or high-volume automated scanning;
- do not access, modify, or keep data that is not yours, and stop as soon as you confirm a finding; and
- give us a reasonable window to fix the issue before publishing it.
If you follow those principles in good faith, we will treat your research as authorised and we will not pursue action over it.
How this website is built
swelv.io is a statically rendered marketing site. It has no user accounts, no login, no payment flow, and no connection to the databases behind the swelv platform. There is no customer or fund data on this site to compromise. Pages are served over TLS, and the only data collected is described in our Privacy Policy.
Payment instructions and wire fraud
Capital calls are a standing target for business email compromise, and the losses are large: the FBI’s Internet Crime Complaint Center recorded $2.77 billion in reported BEC losses in 2024 alone.
So, plainly: swelv will never email you to change bank details. Payment details for a capital call are issued through the platform against the fund’s connected account, never as an ad hoc message from an individual. If you receive anything that looks like a change of payment instructions, a new account number, or an urgent request to redirect a wire, treat it as fraudulent until you have confirmed it by phone on a number you already had.
If something claiming to be from swelv looks wrong, forward it to info@swelv.io before you act on it.
Contact
Security questions, diligence requests, and vulnerability reports all go to info@swelv.io.