SECURITY & TRUST
Trust your product context with Specky.
Everything your security team needs to evaluate Specky
SOC 2 alignment, GDPR and CCPA compliance, encryption details, data residency, sub-processors, DPA, and incident response — all in one place.
- Workspace data is never used to train AI models
- EU data residency available
- Consent, access, and audit controls
Compliance status
We continuously align with leading security frameworks. Below is the current status of each certification or compliance regime.
SOC 2 controls
Security controls mapped to the SOC 2 Trust Service Criteria. The independent Type II audit is in progress; current control documentation and evidence are available for procurement review.
GDPR (EU)
GDPR-focused controls and processes. A Data Processing Agreement (Art. 28) is available, and data subject rights (Art. 15–20) are self-serviceable from workspace settings.
UK GDPR
Aligned with UK GDPR (retained from the EU GDPR post-Brexit). International Data Transfer Agreements (IDTA) available for UK-to-non-UK transfers.
CCPA / CPRA
CCPA / CPRA-focused controls. Opt-out mechanisms, data deletion, and right-to-know requests are supported.
ISO 27001
ISO 27001 Information Security Management System certification is on the roadmap for 2026. Controls are being implemented to meet the standard.
HIPAA
Do not process protected health information (PHI) on a standard plan. Contact us before any PHI is processed so we can confirm whether a BAA and suitable deployment are available.
How we handle your data
Your product data is sensitive. Here's a precise account of where it goes, who can see it, and how it's protected.
Does Specky train AI models on my data?
Where is my data stored?
What are my GDPR rights?
How long is my data retained?
Do you have a Data Processing Agreement (DPA)?
Who are your sub-processors?
Infrastructure & encryption
Specky is built on managed infrastructure with layered controls for managed data, transport, and configured integration-secret wrapping.
Encryption at rest
- Supabase-managed encryption at rest for database and storage
- Row-level security (RLS) enforced on every database query
- AES-256-GCM wrapping for integration secrets when TOKEN_ENCRYPTION_KEY is configured
Encryption in transit
- TLS 1.3 on all client-server connections
- HSTS enforced (2-year max-age, preload)
- Certificate Transparency monitoring
- Perfect Forward Secrecy (PFS) on all sessions
Infrastructure
- Hosted on Supabase (PostgreSQL) + Vercel Edge
- Current EU deployment uses the Frankfurt region
- 99.9% uptime target; commercial SLA terms are agreed separately
- Daily automated backups, 30-day retention
Monitoring & availability
- 24/7 infrastructure monitoring and alerting
- Real-time anomaly detection on auth events
- Health check endpoint for external monitoring
Identity & access management
Specky currently supports email/password and Google OAuth, with workspace membership roles and a documented, flag-gated SAML activation path.
Authentication
- Email + password (Supabase Auth)
- Google OAuth 2.0
- SAML SSO scaffold — disabled by default; requires Supabase and customer IdP setup
Workspace roles
- Owner — full admin access
- Admin — manage members & settings
- Member — workspace access
- Editor / commenter / viewer — document sharing roles
Session management
- JWT tokens with short expiry (1hr)
- Refresh token rotation on every use
- Force-logout all sessions (self-serve)
- Admin session revocation
- Device tracking & audit logging
API security
- Workspace-scoped API keys
- Revocation and expiry checks
- Rate limiting on supported endpoints
- HMAC-signed webhook payloads where configured
Audit logging
- Security-relevant auth events
- Data access, export, and deletion events
- Admin, billing, and integration events
- AI and agent activity metadata
- Workspace-scoped retention and cleanup
SAML activation path
- Flag-gated Supabase Auth SAML flow
- Per-customer IdP registration is required
- Existing callback handles the PKCE session exchange
- SCIM, JIT provisioning, and custom attribute mapping are not implemented
Third-party sub-processors
We maintain a complete list of sub-processors with access to customer data. We notify customers 30 days before adding a new sub-processor. Last updated: September 2026.
| Processor | Purpose |
|---|---|
| Supabase | Database, Auth, Storage |
| Vercel | Compute & Edge Network |
| Google Generative AI | AI inference (Gemini) |
| Stripe | Payment processing |
| PostHog | Product analytics (opt-in) |
| Resend | Transactional email |
| Google Analytics | Marketing analytics (opt-in) |
| Upstash | Rate limiting and caching |
Want the full sub-processor list with DPA annexes? Email security@specky.space
Incident response & disclosure
We take security incidents seriously. Here's what happens when something goes wrong.
Breach notification
We notify affected customers within 72 hours of confirming a data breach, meeting GDPR Art. 33/34 and CCPA requirements. Notification includes nature of the incident, data affected, and remediation steps.
Response SLAs
Critical security incidents: 1-hour initial response, 4-hour containment target. High-severity issues: 4-hour response, 24-hour resolution target. All security issues: 5 business days.
Vulnerability disclosure
We operate a responsible disclosure programme. If you find a vulnerability, email security@specky.space with details. We'll respond within 2 business days and credit you in our Hall of Fame if you wish.
Penetration testing
Security evidence and any available penetration-test summaries can be requested from security@specky.space. We confirm the current materials and scope before sharing them under an appropriate NDA.
Security FAQ
Can I use Specky if I'm subject to HIPAA?
Do you offer on-premise or VPC deployment?
How do you handle AI sub-processors and data residency?
Can I get a security questionnaire filled out?
What happens to my data if I cancel?
How are API integrations secured?
Still have security questions?
Our security team responds to all enquiries within one business day. We can provide current SOC 2 control materials, DPAs, security-questionnaire responses, and available pen-test summaries.
Last reviewed: April 2026 · Next review scheduled: October 2026