Trust Center

How We Earn
Your Trust

Trust is earned with specifics, not badges. Here's what's true today about how we host, protect, and govern it, including what's still in progress. For encryption, access control, and audit logging, see our Security page.

Data Location

Sparko is hosted on AWS in Singapore (ap-southeast-1), with data replicated across multiple availability zones within that region for redundancy.

Business Continuity

Automated backups run continuously with 35 days of retention and multi-AZ replication for high availability.

A restore has not yet been drilled to a measured RTO/RPO. That runs ahead of our first enterprise engagement, alongside the penetration test.

Vulnerability Management

Every change is scanned before and after merge: dependency audits, static analysis for security issues, and container image scanning, plus automated weekly dependency updates.

A third-party penetration test is planned ahead of our first enterprise engagements, rather than run early for its own sake.

Incident Response

We maintain a documented, severity-tiered incident response process with defined escalation paths and a post-incident review for every event, so lessons get fixed into the process.

Customers are notified without undue delay for any incident affecting their data.

Subprocessors

We use a small, named set of subprocessors: infrastructure hosting and backups, AI processing, content delivery, and payment/e-signature processing.

See the full current list with purpose and role in our Data Processing Agreement.

AI Security

Sparko never trains AI models on your data. Résumé parsing and AI screening strip names, contact details, and identifiers like SSNs before any prompt is sent, and the Ask Sparko assistant works from employee IDs and permission-scoped records rather than names. Every AI-proposed action requires explicit human approval before it runs.

More detail on our AI approach is on the Security page and the Ask Sparko page.

Assurance Roadmap

We don't hold SOC 2 or ISO 27001 certification yet. We're building out the underlying controls and evidence first, and will pursue formal certification based on customer demand rather than collecting it for its own sake.

Security Contact

Report a suspected vulnerability to [email protected]. Tell us what you found and how to reproduce it; we’ll acknowledge your report and keep you updated as we work on it.

We won’t pursue legal action against good-faith research that respects customer data and avoids privacy violations, service disruption, or data destruction. Machine-readable contact details are at /.well-known/security.txt.

Have Security or Compliance Questions?

We're happy to walk through our practices in detail, including the gaps we've named above, and where they sit in our plans.

Contact UsSecurity Page