Security & Compliance
Spara's security posture, compliance frameworks, and data handling practices.
Spara is built to be enterprise-grade, so security and compliance are paramount to us.
What compliance frameworks does Spara conform to and audit?
Spara is SOC 2 Type II and GDPR compliant. Please visit our Trust Center for:
Latest reports
Company policies
Subprocessor information and notification subscription
What is Spara's privacy policy?
Spara's privacy policy is available on our website at spara.com/privacy.
Where is Spara hosted?
We are hosted on Google Cloud, which is backed by the same infrastructure and security that Google uses for its own services.
Customer data is stored in U.S. data centers. Some data (HTML pages & assets) may be cached in other geographies by our CDN. Access to private content through our CDN is always validated through our application servers using a complex permissions system.
Google follows or even leads most of the industry's best-practices and is compliant with most major security standards and certifications.
Is customer data encrypted?
Yes, all customer data is encrypted at rest and in-transit via Cloudflare. At rest on Google Cloud Platform, using multiple layers of AES256-AES128.
How does Spara handle PII?
PII is only stored on our production database with strict RBAC. All data is anonymized before porting to lower environments.
How are users authenticated?
Spara supports SSO/SAML authentication as well as email/password authentication. In the case of email/password authentication Spara requires the password to be:
At least 8 characters long.
At least one uppercase character
At least one lowercase character
At least one number
Not be a known compromised password
Are inactive users automatically logged out of Spara Platform?
Yes. By default, inactive users are logged out after 24 hours of inactivity. You can update this setting to any length of time in order to comply with your company's compliance mandate.
Does Spara support Okta single sign-on?
Yes. Spara supports Okta for enterprise SSO via SAML, OAuth 2.0, and OpenID Connect, alongside Microsoft Active Directory and Google Workspace. Contact your customer success representative to enable SSO for your account. See User Management for details.
Does Spara have endpoint protection (EDR) in place?
Yes. Endpoint anti-malware and threat-detection software is deployed on all company-issued endpoints, with central management and continuous monitoring. Definition and engine updates install automatically, files are scanned on introduction and on access, modification, or download, and disabling protections is a policy violation. Email threat detection is also in place.
Does Spara perform SAST and DAST scanning of its systems?
Yes. Application code is scanned prior to deployment. Dependencies are continuously scanned in CI/CD via GitHub Dependabot. Vulnerability scans are performed at least quarterly against public-facing production systems, and penetration tests are performed at least annually. Findings are remediated on the following timeline:
Critical and High — within 30 days
Medium — within 60 days
Low — within 90 days
Does Spara use a cloud security posture management (CSPM) tool?
Yes. Spara's Google Cloud environment is continuously evaluated against the SOC 2 Type II cloud-hardening control set — IAM least-privilege, MFA-enforced production access, encryption at rest and in transit, VPC and subnet isolation, firewall and DDoS controls, tamper-resistant logging, and real-time alerting — supplemented by Google Cloud-native security tooling. Spara's SOC 2 report and underlying control tests are available at the Trust Center.
Will customer data be used to train AI models — by Spara or its subprocessors?
No. Spara does not train AI models on customer data. Spara's contracts with all LLM subprocessors (including OpenAI and Anthropic) include no-training clauses that prohibit the use of customer inputs or outputs for model training. The same commitment is reflected in Spara's customer DPA. The current subprocessor list is available at trust.spara.com/subprocessors.
Does Spara have zero-data-retention agreements with LLM subprocessors?
Yes. Spara has zero data retention (ZDR) agreements in place with its key LLM subprocessors, including OpenAI and Anthropic, and ZDR is enabled by default for those subprocessors.
For LLM subprocessors not covered by ZDR, the provider's standard retention policy applies. All LLM subprocessors are contractually bound by the no-training clauses described above, so customer data is not used to train models. The current subprocessor list is available at trust.spara.com/subprocessors.
Last updated