HR data is among the most sensitive in any organization. Sparko is built with security and privacy at its core, not as an afterthought.
All data is encrypted at rest using AES-256. Sensitive database fields like salary and personal information carry an additional layer of field-level encryption, isolated per customer. Uploaded files (résumés, documents, and payslips) are encrypted at rest via AWS KMS.
All connections use TLS 1.2+ encryption. HTTPS and HSTS enforced on all endpoints, with a two-year max-age covering every subdomain.
Hosted on AWS with multi-availability zone redundancy. Your data is always accessible and protected by AWS's enterprise-grade security.
Continuous automated backups with point-in-time recovery. Multi-AZ replication for high availability. Backup copies retained per our data retention policy.
Unprogressed candidate résumés follow a 12-month retention policy. See our Privacy Policy and Data Processing Agreement for the full retention schedule by data category.
Granular permission controls let you define exactly who can see and do what. Admins, managers, and employees each see only what they need.
SSO, MFA, and passkeys included starting on the Core plan, never gated behind a higher tier.
Visibility into authentication events and data changes for security monitoring.
Sparko never trains AI models on your data. AI providers are used only to serve you in real time, not to build or improve their models on your data.
We're happy to discuss your specific requirements and walk through our security practices. To report a suspected vulnerability, email [email protected].