Your data security is our highest priority
SPHIOR is built with security-first architecture. We publish our security practices, compliance roadmap, and subprocessor list so you can evaluate our trust posture before onboarding.
SOC 2
Not yet certified
TLS 1.2+
All traffic encrypted
AES-256
Encryption at rest
GDPR
DPA available
How we protect your data
Transport Encryption
All traffic is encrypted with TLS 1.2+. HTTP is automatically redirected to HTTPS. HSTS headers are enforced.
Encryption at Rest
All data at rest is encrypted with AES-256. Database backups and object storage use provider-managed encryption keys.
Access Control (RLS)
Row-Level Security ensures tenant isolation at the database layer. Each customer can only access their own data. Admin endpoints are MFA-protected.
Credential Protection
Enterprise authenticated scanning uses AES-GCM 256-bit client-side encryption with HKDF-derived two-layer key architecture. Plaintext credentials exist only in memory during scan execution and are destroyed immediately after.
Isolated Scan Environment
Security scanners run in ephemeral containers that are destroyed after each scan. No persistent state is kept between scans.
Continuous Monitoring
Infrastructure health and error rates are monitored continuously, with automated alerting for anomalies.
What you can check yourself
The following can be checked without asking us. The source of the detection engine is published. The verifier is distributed on npm and runs on your own machine using only Node's standard library. The evidence format follows published standards.
Detection uses no language model, so the same input always produces the same finding. Accuracy is measured against a public benchmark, and that measurement runs as a gate in the build.
A structured response, with the times we aim for
Detection & Triage
Automated monitoring detects anomalies and alerts us directly. Severity is triaged on receipt.
Containment
Isolate affected systems. Revoke compromised credentials. Preserve forensic evidence.
Customer Notification
Affected customers are notified with impact scope and recommended actions.
Remediation & Post-mortem
Root cause analysis, permanent fix deployed, and post-incident review published.
Clear retention periods with right to deletion
| Data Type | Retention | Purpose |
|---|---|---|
| Scan Results | 13 months | Year-over-year comparison and trend analysis |
| Database Backups | 7 days PITR | Point-in-time recovery for disaster scenarios |
| Ephemeral Scan Payloads | 0 — immediate | No persistence; destroyed after execution |
| Account Data on Deletion | 30 days | Grace period; then permanently purged |
| Audit Logs | 12 months | Security investigation and compliance |
Third-party providers that process data
We minimize the number of subprocessors and carefully evaluate each provider's security posture before integration. This list is updated whenever a subprocessor is added or removed.
| Provider | Purpose | Data Processed | Location |
|---|---|---|---|
| Database Provider | Data storage, authentication & access control | Account data, scan metadata, access-controlled records | US |
| CDN & Edge Provider | Content delivery, edge compute, encrypted object storage, DDoS protection | Scan artifacts | Global |
| Application Host | Application hosting and request processing | No persistent customer data; ephemeral request processing | Global (Edge) |
| Cloud Infrastructure | Security scanner execution in isolated, ephemeral containers | Ephemeral scan payloads; destroyed after execution | Asia-Pacific (Tokyo) |
| Payment Processor | Payment processing, subscription billing, invoicing | Payment tokens only; SPHIOR never stores card numbers | US / EU |
| AI Provider | Generating responses for the SPHIOR AI assistant. | The text of the question you send to the assistant. | US |
| Email Delivery | Transactional email — sign-in, notifications and alerts. | Recipient email addresses, delivery metadata | US |
Responsible disclosure policy
We welcome security researchers to report vulnerabilities in SPHIOR's services. We commit to acknowledging reports within 3 business days, providing an initial assessment within 10 business days, and resolving confirmed vulnerabilities within 90 days.
Scope
In scope
sphior.com and its API endpoints
Response SLA
Acknowledgment < 3 days, Assessment < 10 days
Fix SLA
Critical < 30 days, High < 60 days, Others < 90 days
Safe harbor
Good-faith researchers will not face legal action
Generate your DPA automatically
Our system generates a legally compliant DPA covering GDPR, CCPA, and APPI. Fill in the form below and your signed PDF will be ready shortly.
Last updated: 2026-09-08
Questions about our security practices? Contact security@sphior.com
