Evaluation checklist
What to look for in a survey data delivery platform
Fourteen questions worth asking before you choose where your point clouds, orthomosaics, scans and drone data go when they leave your office. Each one has Swyvl's answer, including the two it cannot yet say yes to. Ask every vendor the same fourteen.
1. Does the client need software or an account to open it?
YesNo. A share link opens in any browser with nothing to install and no login. You can add a password or restrict the link to named people, and change that after it has been sent.
2. Can it open the formats we deliver?
YesPoint clouds (LAS, LAZ, E57, PTX, PTS, XYZ, PLY), orthomosaics and DEMs (GeoTIFF, COG), 3D Tiles, meshes (GLB, glTF, OBJ, FBX, STEP, IGES), BIM (IFC), CAD (DXF), Gaussian splats (PLY, SPZ, KSPLAT, .splat), Xgrids LCC and LCC2, vector data (GeoJSON, KML, KMZ, SHP, GPX), drone video with GPS (DJI SRT), 360° photos and video, PDFs and images. A file with no viewer is still stored and downloadable, and the card says why.
3. Can we send everything from a job in one link?
YesYes. A share link covers a site, so every file from the job goes out on one link, each in its own viewer, with a filmstrip between them. Files can be added after the link has been sent, and a link can be set to include future uploads.
4. Can the client measure on it?
YesYes. Point, distance, area and height tools on every 3D and map viewer, on the hub and on share links, on every plan. Every measurement carries a badge saying which frame its numbers are in. Measurements are for the session and are not saved. There is no volume tool.
5. Can we control viewing versus downloading?
PartlyPer link, yes: view-only or view-and-download, and you choose which files each link includes. Download rights are set per link, not per file within one link.
6. Can we restrict a link to named people, or password it?
YesYes. Open to anyone with the URL, password-protected, or restricted to named people by email. Passwords are enforced on the server with lockout after repeated failures. All three can be changed after the link has gone out, and a link can be revoked at any time.
7. Is there an audit trail of who opened what, when and from where?
YesYes. Every view is logged with the time, the file and where it was opened from, and appears in the site's activity feed straight away. The log is append-only at the database level and is kept for two years. A weekly digest summarises views across your sites.
8. Is each delivery dated, and can we see a site over time?
YesYes. Every upload becomes a dated collection on a permanent site. In your workspace the site's timeline lays the collections out by date. A share link set to include future uploads shows each new collection as it lands.
9. Where is the data stored, and does it leave that region?
YesYou choose one of eight regions when the organisation is created: Australia, US East, US West, United Kingdom, Europe, Canada, Japan or Singapore. Files are stored in that region and are not moved out of it. The region is fixed for the life of the organisation.
10. Can we get everything back out in standard formats?
YesYes. Every original file stays downloadable in the format you uploaded, and derived versions are open standards: COPC, COG, 3D Tiles, GeoJSON. On cancellation the account enters a 30-day read-only export period.
11. Can the client upload back to us?
YesYes. A share link can accept uploads, so a client or subcontractor sends files into the site without an account. Turn it on or off after the link has been sent.
12. Can we brand it?
YesYour logo and colours on every share link on paid plans. Full white-label, with no Swyvl branding, on Enterprise.
13. Can we control who in our own team sees what?
YesTwo levels. Organisation roles (owner, admin, member) govern billing, seats and settings. Workspace roles (owner, editor) govern access to the data. Contractors can be invited as editors and removed when the contract ends; the data stays with the site.
14. Single sign-on and SAML?
On requestGoogle sign-in and passwordless email sign-in with optional two-factor authentication are standard on every plan. SSO/SAML is an Enterprise feature, available on request and scoped per engagement.
15. Is it certified?
Not yetNot yet. Swyvl's controls are aligned to ISO 27001 and SOC 2 and mapped in a control register, and SOC 2 Type I is the first certification target. In place today: passwordless sign-in with optional two-factor, row-level access control on every table, an append-only audit log kept for two years, encryption in transit and at rest, region-locked file storage, no training on customer data and file contents never sent to AI, a published subprocessor list, and access-review, personnel, change-management and secrets policies. A supplier security questionnaire is available on request.
The checklist, to paste into your own evaluation
- Does the client need software or an account to open it?
- Can it open the formats we deliver?
- Can we send everything from a job in one link?
- Can the client measure on it?
- Can we control viewing versus downloading?
- Can we restrict a link to named people, or password it?
- Is there an audit trail of who opened what, when and from where?
- Is each delivery dated, and can we see a site over time?
- Where is the data stored, and does it leave that region?
- Can we get everything back out in standard formats?
- Can the client upload back to us?
- Can we brand it?
- Can we control who in our own team sees what?
- Single sign-on and SAML?
- Is it certified?
See it answered in practice: use cases by problem · features · security documentation · subprocessors