Security and privacy are built into how we design, run and support Spekit. This page gives a quick overview of our security program.
1. Compliance
- SOC 2 Type II: Spekit is independently audited against the SOC 2 Trust Services Criteria. You can request the latest report from the Trust Center.
- GDPR and CCPA: See the Trust Center FAQ and our Privacy Policy for details.
- Sub-processors: The current list of Spekit sub-processors and where each one stores data is published in the Trust Center.
2. How We Protect Your Data
| Area | Controls in Place |
|---|---|
| Data security | Encryption in transit and at rest, with daily database backups. |
| Infrastructure | Hosted across multiple availability zones, with security patches applied automatically and restricted access to cloud data storage. |
| Application security | Annual third-party penetration tests, quarterly vulnerability scans, a web application firewall, and peer code review within a defined software development life cycle. |
| Access control | Multi-factor authentication, unique accounts, session lock, and restricted access to server administration. |
| Monitoring | Servers, databases and message queues are continuously monitored and alarmed. |
| Our people and processes | Security training for all employees, a dedicated incident response team and plan, and business continuity and disaster recovery plans that are tested every year. |
3. AI and Your Data
If you use Spekit's AI features, such as AI Sidekick and AI content recommendations, our Spekit AI Data Privacy & Security FAQs and the Trust Center explain what data those features use and how it is transmitted and protected. To learn more about our approach, read A letter from the CTO: Spekit's commitment to data security and privacy in an AI-first world.
4. Security Documentation You Can Request
The Trust Center hosts the documents security and procurement teams usually ask for, including:
- SOC 2 Type II report
- Latest penetration test summary
- CAIQ (Consensus Assessments Initiative Questionnaire)
- Security and GRC overview, and our production architecture diagram
- Policies, including access control, vulnerability management, change management, business continuity and responsible disclosure
5. Questions or Reporting a Concern
If you can't download a document from the Trust Center, or you have a security question or want to report a potential vulnerability, email security@spekit.co. For product help, see How to contact Spekit Support.