Security
Safe, private, and yours to control.
Your business data runs everything you do. We protect it with real controls.
Encrypted in transit
TLS 1.2+ on every connection, and stored mailbox and calendar credentials sealed with AES-256-GCM before they reach the database.
Access you govern
Two-factor authentication, granular roles enforced server-side, and an audit log so only the right people see the right things.
Your data stays yours
We never sell it or train third-party models on it. Export anytime.
Data & encryption.
- In transit
- TLS 1.2+ (HTTPS) on every connection, with modern ciphers.
- At rest
- Connected-mailbox credentials are encrypted with AES-256-GCM. Database storage is access-controlled on dedicated hardware, not separately encrypted.
- Isolation
- Each workspace's data is logically separated; queries are always scoped to your workspace.
- Backups
- Automated nightly backups, kept 14 days, and mirrored the same night to a second, independent host that keeps 30.
Access & identity.
Control who gets in, and exactly what they can do.
- Two-factor auth
- Available on every plan for every user.
- Roles & permissions
- Role-based access, with advanced granular permissions on Business.
- Audit log
- Per-record history on every plan; the workspace audit log — deletions, exports, role and settings changes — on Business.
- Not available today
- SSO/SAML, SCIM provisioning and IP allowlisting are not built. We'd rather say so than sell you one.
Infrastructure & reliability.
- Hosting
- Spodus Cloud runs on dedicated Hetzner infrastructure in Nuremberg, Germany, fronted by Cloudflare for DNS, TLS and DDoS protection.
- Backups & recovery
- Nightly backups mirrored to a second host, with a documented restore procedure. Recovery point is the last nightly run, so up to 24 hours of changes could be lost.
- Data location
- All Spodus Cloud data is stored in Germany, inside the EU. We don't offer other regions today, and we'd rather say so than sell you one.
Sub-processors.
Every third party that touches your data, named, with what it does and where it runs.
| Provider | Purpose | Location | Certifications |
|---|---|---|---|
| Hetzner | Application hosting, database & backups | Nuremberg, Germany | ISO 27001:2022, PCI DSS 4.0 |
| Cloudflare | DNS, CDN, TLS termination & DDoS protection | Global edge network | SOC 2 Type II, ISO 27001, PCI DSS Level 1 |
| Stripe | Payment processing for Spodus subscriptions | United States | PCI DSS Level 1, SOC 2 Type II |
| Resend | Transactional & notification email | United States | SOC 2 Type II |
Certifications listed are held by each provider, not by Spodus. Ask us and we’ll point you to the current scope documents. See the full sub-processor list for change notifications.
On compliance, plainly.
We won’t claim certifications we don’t hold. Spodus carries neither SOC 2 nor ISO 27001, and you won’t find those badges on this page. What we can show you is verifiable: every sub-processor named above with its own certifications, our processor commitments written down in a data processing agreement you can read before you sign anything, a privacy notice that says plainly what we collect and why, and a vulnerability disclosure policy with a safe harbour for good-faith research.
Spodus is sold to businesses in the United States. You can export or delete your data at any time. If your procurement needs a badge today, talk to us about your requirements rather than assuming the answer is no.
Questions, answered.
How is my data encrypted?
Who at Spodus can see my data?
How often do you back up, and can I get my data out?
Do you hold SOC 2 or ISO certifications?
Where is my data stored?
How do I report a vulnerability?
Questions about security?
Tell us what your team or your auditors need, and we'll give you straight answers.