// security is the product
A guard, not a gambler.
A black box touching your operations is terrifying. It should be. So the whole system is built to make the risky parts safer, with guarantees you can read and switch off, and a sub-processor list we publish in full. And no certificate we don't actually hold.
Inherited from the stack your build runs on (Vercel · Supabase · Anthropic). Sponte's own org-level audit is on the roadmap. The full, verifiable breakdown is below.
// the perimeter
Every line of the build is readable and inspectable. No vendored black box, and nothing happens off the record.
It runs on Supabase and Vercel, certified infrastructure with configurable regions, EU by default for EU businesses.
Credentials are vaulted and scoped. Rotate them, scope them, or shut the system down entirely, in one move.
// provable by architecture
Provable by architecture, not by promise.
The safest claim is the one you can check yourself. These hold because of where the system runs, not because we say so.
4
sub-processors in the whole data path
published in full in the DPA
1
policy gate in front of every agent action
deny-by-default, scoped before deploy
100%
of agent actions written to the audit trail
hash-chained, append-only
0
actions above scope without human approval
risky moves wait for a checkpoint
// the guarantees
A set of guarantees you can read and switch off.
RLS as a database guarantee, not app-code hope. One client's data never bleeds into another's, enforced at the row, not the request.
A least-privilege role behind a policy gate. Agents only do what they're scoped to, never free-form actions on anything that moves money or data.
Hash-chained and tamper-evident. A readable record of every action the system takes: every ticket answered, every record written, every job queued.
Revokes credentials on demand. If anything feels wrong, one switch and the system can't touch your data until you say otherwise.
Every agent's reach is scoped before deploy, not discovered after. The support agent answers a ticket. It cannot issue a refund or touch billing.
Anything irreversible, a refund, a payment, an outbound send, waits behind an approval threshold you define. The machine drafts, a human commits.
// compliance, honestly
Where every standard actually stands.
Most of your compliance comes from the certified infrastructure your build runs in. We tell you exactly what is inherited, what is contractual, and what is still on our roadmap. Green is real today. Amber is honest about what isn't.
| area | where it stands | status |
|---|---|---|
| GDPR | Operated from the Netherlands under GDPR. Builds default to EU regions. We publish a real DPA and the full sub-processor list. | EU-based |
| SOC 2 Type II · ISO 27001 | Your build runs on Vercel and Supabase: SOC 2 Type II, ISO 27001, HIPAA and PCI DSS, AES-256 at rest, TLS in transit. | inherited |
| AI providers | Anthropic / OpenAI on commercial terms: SOC 2 Type II and ISO 27001/42001. Your inputs and outputs never train a model, logs auto-delete, zero-retention available. | contractual |
| SSO · SAML | Auth runs through your identity provider via Supabase Auth. No separate Sponte login to provision, manage, or offboard. | your IdP |
| Per-build security spec | Agent permissions, approval thresholds, data flows and incident steps, written and signed by both sides before anything deploys. | signed |
| Sponte org SOC 2 / ISO | Not separately certified yet. We won't print a badge we don't hold. The verifiable architecture above stands today, the formal audit is on the roadmap. | roadmap |
// controls, per build
The same controls, applied to every build.
Pull requests, staged deploys, documented rollback.
Least-privilege credentials, scoped per agent, revocable in one move.
Vaulted secrets, data minimization, and no model training, ever.
AES-256 at rest, TLS in transit, inherited from Supabase + Vercel.
Platform SLAs, health checks, and alerts on the running system.
Dependency scanning and a patch procedure on every build.
A per-build runbook and a one-switch kill on demand.
A pre-deploy security review and approval thresholds on risky actions.
Private networking where possible, TLS on every external call.
Your action log is retained on your terms, AI provider logs auto-delete.
Agents read only the fields they need, nothing extra is ever moved.
A named operator and a signed security spec before deploy.
// the trail
Every action is scoped, logged, and reversible.
Each step the system takes passes a policy gate, then writes itself to a hash-chained log you can read. Nothing happens off the record, and nothing happens outside its scope.
rendered preview of the audit surface, exactly what your dashboard streams
// sub-processors
Most vendors need a long sub-processor table. Ours is short, and published.
The architecture keeps most third parties out of the path entirely. Here is the short list of who is in it, and why. The canonical, dated version lives in the data processing addendum.
| provider | purpose | region |
|---|---|---|
| Vercel | Hosting + edge delivery for the build | Configurable region |
| Supabase | Postgres database + auth, with RLS | Your project's region |
| Anthropic / OpenAI | Model inference, the reasoning step only | US / EU |
| Sentry | Error + uptime monitoring, PII scrubbed | EU option |
// straight answers
The questions a security team actually asks.
Do you hold SOC 2 Type II or ISO 27001?
Not as a Sponte organization certificate, not yet, and we won't print a badge we don't hold. But your build runs on Vercel and Supabase, which are both SOC 2 Type II and ISO 27001 certified, with AES-256 encryption at rest and TLS in transit. The AI reasoning step (Anthropic) is SOC 2 Type II, ISO 27001 and ISO 42001. You inherit those controls because the system runs on that stack. Sponte's own formal audit is on the roadmap.
Where is my data hosted?
On Supabase and Vercel, in a configurable region. We default to EU regions for EU businesses. Every party that touches the path is named in the published sub-processor list, so there's nothing to guess.
Is my data used to train AI models?
No. Under Anthropic's and OpenAI's commercial and API terms, your inputs and outputs are never used to train models. API logs auto-delete within days, and a zero-data-retention mode is available for the most sensitive workloads.
Do you support SSO and SAML?
Yes, through your identity provider. Auth runs on Supabase Auth, so the system works with your existing SSO/SAML and access policies. There's no separate Sponte login to provision or offboard.
Who can access my systems after the build?
Only what's scoped, and everything is on the record. Access is least-privilege per agent, every action lands in the hash-chained audit trail, and risky moves wait for your approval. You hold the kill switch: one move and the system can't touch your data.
What happens if Sponte disappears tomorrow?
Nothing breaks. The system runs on standard infrastructure with readable code, full documentation, and a runbook. Any competent engineer can read and maintain it. Continuity is designed in, not promised.
Is the system penetration tested?
We run dependency scanning and a written pre-deploy security review on every build, and the underlying platforms are independently penetration-tested. A formal third-party pen test of a specific Sponte build is something we scope per engagement rather than claim as a blanket badge.
Are you GDPR compliant?
We operate from the Netherlands under GDPR, default to EU data residency, and publish our full sub-processor list. The formal DPA text is being finalized with counsel, and we say exactly that instead of shipping boilerplate.
// where we are, honestly
We're early, and we won't print a certificate we don't hold. What we do hold is the architecture above, isolation, audit, kill switch, scoped blast radius, that you can verify line by line before you commit a dollar, plus the inherited certifications of the stack it runs in. Formal SOC 2 and ISO work is on the roadmap, not on a badge.
Security questions before a build? Bring them to the audit call. We answer in readable code, not a slide.
See the guard run on your real workflow.
15 minutes, no deck. We map your perimeter, show the controls live on a real build, and you decide from what you see.