Security and compliance
Trust Center
We ask customers to route their most sensitive telemetry through our platform, so this page sets out how that data is handled, who else touches it, and how to reach us about a security issue.
Handling customer data
Where customer data lives
Each deployment runs within a customer-designated region. Security telemetry is processed inside that boundary, and is not pooled with other customers' data or used to train a shared model.
Tenant separation
Every customer environment has its own context and retrieval architecture. Separation is structural rather than policy-based, so there is no cross-customer path for intelligence to leak along.
Retention
Retention windows are set per deployment and agreed in the contract. Customers can request export or deletion of their data at any time, and deletion propagates to derived stores.
Encryption
Data is encrypted in transit with TLS 1.2 or above, and at rest using AES-256.
Certifications
Spharaka does not currently hold ISO 27001 or SOC 2 certification, and this page will state the certificate and its scope when that changes. We would rather be accurate here than imply an assurance we cannot evidence. Customers running a vendor assessment can request our security questionnaire responses, architecture documentation and data-flow diagrams directly.
Request security documentationSub-processors
Third parties involved in operating this website and our services. Customer security telemetry is not shared with any of them.
| Provider | Purpose | Region |
|---|---|---|
| Cloudflare | Website delivery, DNS and edge security | Global edge |
| Google Analytics | Website traffic measurement | EU / US |
| Ahrefs Analytics | Website traffic measurement | EU |
Reporting a vulnerability
If you believe you have found a security issue in this website or in our platform, email [email protected]. Please include enough detail to reproduce the issue. We aim to acknowledge reports within three business days and will keep you updated while we investigate.
We ask that you give us a reasonable window to remediate before disclosing publicly, and that testing avoids privacy violations, service degradation and data destruction. We will not pursue action against researchers who act in good faith within those bounds.