Security-First Design

Your Data Security is
Our Priority

HR data is among the most sensitive in any organization. Sparko is built with security and privacy at its core, not as an afterthought.

AES-256
Encryption
AWS
Infrastructure
SSO/MFA
Every Plan
Audit
Logging

Data Protection

Encryption at Rest

All data is encrypted at rest using AES-256. Sensitive database fields like salary and personal information carry an additional layer of field-level encryption, isolated per customer. Uploaded files (résumés, documents, and payslips) are encrypted at rest via AWS KMS.

Encryption in Transit

All connections use TLS 1.2+ encryption. HTTPS and HSTS enforced on all endpoints, with a two-year max-age covering every subdomain.

Secure Infrastructure

Hosted on AWS with multi-availability zone redundancy. Your data is always accessible and protected by AWS's enterprise-grade security.

Automated Backups

Continuous automated backups with point-in-time recovery. Multi-AZ replication for high availability. Backup copies retained per our data retention policy.

Data Retention

Unprogressed candidate résumés follow a 12-month retention policy. See our Privacy Policy and Data Processing Agreement for the full retention schedule by data category.

Access Control

Role-Based Permissions

Granular permission controls let you define exactly who can see and do what. Admins, managers, and employees each see only what they need.

  • Custom role creation
  • Field-level permissions
  • Action-level restrictions
  • Department-based access

Authentication Security

SSO, MFA, and passkeys included starting on the Core plan, never gated behind a higher tier.

  • Multi-Factor Authentication (TOTP)
  • Passkeys (WebAuthn)
  • SSO with SAML 2.0, Okta & Entra (all plans)
  • Password policy enforcement
  • Session timeout controls

Audit Logging

Visibility into authentication events and data changes for security monitoring.

  • Security audit trail
  • Authentication activity tracking
  • Before/after change tracking
  • Login history

AI & Data Privacy

Sparko never trains AI models on your data. AI providers are used only to serve you in real time, not to build or improve their models on your data.

No AI Model TrainingSparko never trains AI models on your data. A centrally-managed provider key processes your data in real time, and it is never used to build or improve models
Candidate AI Runs on Redacted DataRésumé parsing and AI screening strip names, contact details, and identifiers like SSNs before any prompt is sent. Screening evaluates an anonymized profile, so identity can’t sway the score
The Assistant Works From IDs, Not NamesAsk Sparko builds its prompts from employee IDs and permission-scoped records rather than names, and only ever sees data the asking user already has permission to see, scoped to your workspace
Data IsolationComplete logical separation between customer environments
Human in the LoopAI drafts, scores, and proposed actions are reviewed by a person before anything is applied
Every Approved Action Is LoggedApproving an action records its type, parameters, approving user, and outcome (including failures) to your security audit log, queryable and exportable by admins on every plan

Have Security Questions?

We're happy to discuss your specific requirements and walk through our security practices. To report a suspected vulnerability, email [email protected].

Contact UsTrust Center