Trust

Security you can show an auditor.

Concrete controls, not promises.

  • GDPR · DORA · NIS2

    Platform controls are mapped to GDPR, DORA, and NIS2. Audit evidence and the control-mapping pack are shared under NDA. We do not claim ISO 27001, SOC 2, or HIPAA certification.

  • Where customer data is stored

    xEvolve, Cloud Horizons, and Automate Certificates store product customer data in the shared Supabase Postgres project in the EU (Paris), one schema per customer, and files in Cloudflare R2. Guardrail Ledger and ClearScreen trials use the same project; a paid workspace has its own Supabase project in the region chosen at purchase (Frankfurt for the EU). The hub control plane (accounts, billing, audit log) runs on Cloudflare (Workers, D1, KV, R2, Durable Objects) with no jurisdiction pinned. A workspace bought through Azure Marketplace is hosted on Microsoft Azure instead, in the region the buyer picks (North Europe, West Europe or a US region). Every company that handles customer data is named on the subprocessor list.

  • AES-256 and TLS 1.3

    Data encrypted at rest with AES-256. All client and API traffic uses TLS 1.3. Keys managed through Cloudflare infrastructure.

  • OIDC SSO with Entra

    Sign in through Microsoft Entra ID via OIDC. No shared passwords.

  • Tenant-scoped access

    Entra ID OIDC ties every session to your directory. API tokens and Console actions are scoped to your tenant — no cross-customer access paths. Where each product keeps customer data is stated in the storage section above.

  • Exportable audit evidence

    Login events, Console actions, and configuration changes recorded with actor, IP, and timestamp. Export the audit packet for vendor-risk reviews.

How we isolate customers.

  1. Get your own Environment

    When you sign up, Spot Suite provisions a Customer Environment for your tenant before any product is activated. Your users, sessions, and audit trail are scoped to that Environment.

  2. Scope identity to your tenant

    Entra ID OIDC ties every session to your directory. API tokens and Console actions are tenant-scoped — no cross-customer access paths.

  3. Record and export evidence

    Platform and product events write to your Environment audit log. Download the evidence pack for DORA, NIS2, GDPR reviews, or internal control testing.

Subprocessors

Every outside company that handles customer data: what it receives and where. Checked against our code.

See the subprocessor list

Request the security pack.

Control-mapping pack, DPA, and architecture diagram — available under NDA.