What’s new?
Swif GRC is a FREE self-hosted GRC software hosted by Swif for your SOC2, ISO 27001, HIPAA, NIST, CMMC, etc.
For organizations that already have a comp.swif.ai account linked to Swif:
Clicking Launch a self-hosted GRC software from the Compliance Marketplace now provides a one‑click, seamless launch into Swif GRC whenever possible.
Swif will try to use a cached Swif's API token to open
https://comp.swif.aidirectly, without showing the old “Copy your Swif API key” popup.If the cached token is not available, Swif will skip the old API‑key popup and instead send you straight to the Swif GRC login page.
For organizations that do not yet have a Swif GRC account:
The existing onboarding popup (with Swif API key, Copy button, and Launch button) continues to work exactly as before.
Entry points: where you can launch Swif GRC
You can launch Swif GRC from two places in the Compliance Marketplace:
How the new launch behavior works
1. Existing Swif GRC account with cached token (ideal path)
Who this is for:
Organizations that already use comp.swif.ai and have a valid Swif MDM API token cached from a previous integration.
What happens:
Swif detects that your organization already has a Swif GRC integration and a cached API token.
A new browser tab opens directly to
https://comp.swif.ai.You are automatically authenticated into Swif GRC (no extra Swif prompts, no token copy step).
The Compliance Marketplace UI stays open in Swif; only a new tab is created for CMOP.
Result:
You get a true one‑click launch into Swif GRC, with no interruptions from the old API‑key popup.
2. Existing Swif GRC account but no cached token
Who this is for:
Organizations that are already using comp.swif.ai, but Swif cannot find a cached Swif MDM API token (for example, a new browser, cleared cache, or a reconfigured integration).
What you do:
Go to Compliance → Compliance Marketplace.
Click Launch Swif GRC from either:
the banner, or
the Swif GRC card.
What happens:
Swif detects that your organization has a Swif GRC account, but no usable cached token is available.
Swif does not show the old “Copy your Swif API key” popup.
Instead, Swif opens a new tab to the Swif GRC login page at
https://comp.swif.ai.You log in as usual; once authenticated, Swif GRC works as normal.
Result:
You still avoid the previous, mandatory API‑key dialog. When the token is missing, you’re routed straight to the Swif GRC login screen instead.
3. Organization without a Swif GRC account (onboarding flow)
Who this is for:
Organizations that have not yet created a comp.swif.ai account or integrated Swif with Swif GRC.
What you do:
Open Compliance → Compliance Marketplace.
Click Launch Swif GRC from:
the banner, and/or
the Swif GRC card.
What happens (unchanged):
The legacy “Launch Swif GRC” popup opens.
You’ll see:
Your Swif API key.
A Copy button.
A disabled “Launch Swif GRC” button.
After you click Copy, the Launch Swif GRC button becomes enabled.
Clicking Launch Swif GRC opens
https://comp.swif.aiwhere you can complete onboarding.
Result:
The onboarding flow remains fully backward‑compatible. There is no regression for organizations that are setting up Swif GRC for the first time.
Trust Center
To launch your Organization's public trust portal, learn more at Trust & Transparency Page — Your Organization's Public Trust Portal.



