For the complete documentation index, see llms.txt. This page is also available as Markdown.

Security & Compliance

Spara's security posture, compliance frameworks, and data handling practices.

Spara is built to be enterprise-grade, so security and compliance are paramount to us.

What compliance frameworks does Spara conform to and audit?

Spara is SOC 2 Type II and GDPR compliant. Please visit our Trust Center for:

  • Latest reports

  • Company policies

  • Subprocessor information and notification subscription

What is Spara's privacy policy?

Spara's privacy policy is available on our website at spara.com/privacy.

Where is Spara hosted?

We are hosted on Google Cloud, which is backed by the same infrastructure and security that Google uses for its own services.

Customer data is stored in U.S. data centers. Some data (HTML pages & assets) may be cached in other geographies by our CDN. Access to private content through our CDN is always validated through our application servers using a complex permissions system.

Google follows or even leads most of the industry's best-practices and is compliant with most major security standards and certifications.

Is customer data encrypted?

Yes, all customer data is encrypted at rest and in-transit via Cloudflare. At rest on Google Cloud Platform, using multiple layers of AES256-AES128.

How does Spara handle PII?

PII is only stored on our production database with strict RBAC. All data is anonymized before porting to lower environments.

Contact your customer support representative for details on PII retention and deletion.

How are users authenticated?

Spara supports SSO/SAML authentication as well as email/password authentication. In the case of email/password authentication Spara requires the password to be:

  • At least 8 characters long.

  • At least one uppercase character

  • At least one lowercase character

  • At least one number

  • Not be a known compromised password

Are inactive users automatically logged out of Spara Platform?

Yes. By default, inactive users are logged out after 24 hours of inactivity. You can update this setting to any length of time in order to comply with your company's compliance mandate.

Does Spara support Okta single sign-on?

Yes. Spara supports Okta for enterprise SSO via SAML, OAuth 2.0, and OpenID Connect, alongside Microsoft Active Directory and Google Workspace. Contact your customer success representative to enable SSO for your account. See User Management for details.

Does Spara have endpoint protection (EDR) in place?

Yes. Endpoint anti-malware and threat-detection software is deployed on all company-issued endpoints, with central management and continuous monitoring. Definition and engine updates install automatically, files are scanned on introduction and on access, modification, or download, and disabling protections is a policy violation. Email threat detection is also in place.

Does Spara perform SAST and DAST scanning of its systems?

Yes. Application code is scanned prior to deployment. Dependencies are continuously scanned in CI/CD via GitHub Dependabot. Vulnerability scans are performed at least quarterly against public-facing production systems, and penetration tests are performed at least annually. Findings are remediated on the following timeline:

  • Critical and High — within 30 days

  • Medium — within 60 days

  • Low — within 90 days

Does Spara use a cloud security posture management (CSPM) tool?

Yes. Spara's Google Cloud environment is continuously evaluated against the SOC 2 Type II cloud-hardening control set — IAM least-privilege, MFA-enforced production access, encryption at rest and in transit, VPC and subnet isolation, firewall and DDoS controls, tamper-resistant logging, and real-time alerting — supplemented by Google Cloud-native security tooling. Spara's SOC 2 report and underlying control tests are available at the Trust Center.

Will customer data be used to train AI models — by Spara or its subprocessors?

No. Spara does not train AI models on customer data. Spara's contracts with all LLM subprocessors (including OpenAI and Anthropic) include no-training clauses that prohibit the use of customer inputs or outputs for model training. The same commitment is reflected in Spara's customer DPA. The current subprocessor list is available at trust.spara.com/subprocessors.

Does Spara have zero-data-retention agreements with LLM subprocessors?

Yes. Spara has zero data retention (ZDR) agreements in place with all LLM subprocessors. ZDR settings may be turned on by request for enterprise-level customers.

Even when ZDR is not turned on, default subprocessor retention applies — for example, OpenAI's standard 30-day retention for abuse-monitoring purposes, after which data is deleted. All LLM subprocessors are contractually bound by the no-training clauses described above, so customer data is not used to train models during that retention window. The current key subprocessor list is available at trust.spara.com/subprocessors.

Last updated