Trust centre

How Spectis handles your data.

This page is written for the person who has to sign off on us. It states what the software collects, what it stores, who can read it and where it runs, at the level of detail a security questionnaire asks for. Where something is not yet in place, it says so.

0

network hops added. Spectis observes; it never sits in the request path.

1

subprocessor for the managed service. None at all if you self-host.

Single

tenant per instance, with its own database. No shared data plane.

Never

prompts or completions captured from the coding-agent hook.

Data handling

What leaves an endpoint.

By mode, so you can hold us to it. Each of these is enforced inside the scanner rather than promised by policy, and the same statement is rendered in the product on the integrations page.

Default
MCP inventory and machine facts. Server name, client, transport, package, version, endpoint URL, whether credentials are present, and environment variable names — never their values. Hostname, operating system, OS username, agent version, hardware serial. No raw command lines.
Artifact scan
File facts, and short strings from inside files. Path, type, size, SHA-256 and the frontmatter key names. Also the declared tool and permission values verbatim, truncated at 80 and 60 characters, because which tools a skill granted itself cannot be answered without them. We would rather state that than claim metadata only.
Signals · opt-in
Ten booleans per file. Shell execution, pipe-to-shell, permission bypass, SSH key references, prompt-injection markers and similar. Derived from the file body; the body is then discarded. No matched text, no line numbers.
Review · opt-in
A redacted excerpt of instruction files. Up to 16 KB of the eight reviewable types, redacted before it leaves the endpoint and again on arrival, held in memory for the analysis and dropped. Never written to storage.
Repositories
Findings carry code context. A finding includes a few lines around the match, and that snippet is stored. A snippet matching a credential pattern is never sent at all; the finding carries the credential type, a masked value and the line number instead.
Never
Prompts, completions and conversation bodies from the hook. The hook records what a tool was asked to do and the verdict it received. Personal data appearing in tool output is counted by type, not captured.

What is stored

Retained
Agent runs and tool-call events, detections and their verdicts, inventory rows, scan results, audit events, and the hash and verdict of analysed files.
Not retained
File contents, prompts, completions, environment variable values, raw command lines, and the text of any file sent for analysis.
Retention
Customer-configured. The default is to retain for the life of the instance so the audit trail stays complete; deletion on request is supported, and self-hosted customers control it entirely.
Access

Who can read what.

Roles are enforced server-side on every request, and the separation is structural rather than a setting. The written contract behind this table is available on request.

RoleAggregatesConversation contentConfiguration
ComplianceOrganisation-wide Yes, and every read is auditedThe audit trail of those reads is itself confidential No
SecurityOrganisation-wide Only if the organisation grants itAn audited setting, off by defaultPartial
AuditorOrganisation-wide, read-onlyNoNo
ManagerTheir own reports onlyResolved fail-closed: if the reporting line cannot be established, nothing is returnedNoNo
AdministratorNoneOperates the platform and cannot read who used which AI serviceNoYes

A filter can only ever narrow what a role may already see. Naming a person outside your scope returns nothing and is indistinguishable from naming someone who does not exist, so the filter cannot be used to enumerate the directory.

Infrastructure

Where it runs, and how it is protected.

Tenancy
One instance per customer, with its own orchestrator, dashboard and database. No shared data plane between customers.
Self-hosted
Docker Compose or Helm, in your own cloud or on-premises. Identical to the hosted build. In this model no data reaches us at all and there are no subprocessors.
Region
Selected per customer at provisioning and pinned for the life of the instance.
In transit
TLS 1.3. Commands sent to an endpoint are additionally signed with Ed25519 and carry replay protection; the endpoint verifies the signature before acting.
At rest
Encrypted storage and database volumes. Integration credentials are separately encrypted at the application layer before they are written.
Secrets
Held in AWS Secrets Manager for the managed service, environment-supplied when self-hosted. Never logged, never returned in an error response.
Authentication
Argon2id password hashing, rate-limited sign-in, SCIM provisioning with your directory groups mapped to roles. Single sign-on is on the roadmap and not yet available.
Subprocessors

One, for the managed service.

Most vendors in this category list twenty. We list one because the product is deliberately single-tenant and does almost nothing off-instance.

ProviderPurposeDataLocation
Amazon Web Services Application hosting, database, object storage, secrets, content delivery All customer data held by the managed service Region you select
Analysis
Instruction-file analysis runs on Amazon Bedrock. Connect your own Bedrock account and it runs inside it, in which case it is not a subprocessor at all. Otherwise it runs in the instance's own AWS account, under the entry above. It can also be pointed at a model on your own hardware, or switched off entirely, in which case Spectis falls back to rules.
Your connectors
Microsoft, OpenAI, Anthropic, GitHub, AWS and Google are read using credentials you supply, from your own tenants. These are your vendors, not ours. Spectis reads from them on your instruction and adds no processor of its own; each connector is enabled individually and can be revoked at any time.
Notice of change
Customers are notified before a subprocessor is added. Write to the address below to be added to that notice list.
Certification status

Where we actually are.

SOC 2
Not yet audited. We will state that here until an audit is under way, and publish the report when there is one.
ISO 27001
Not yet audited.
Penetration test
No third-party test yet. An internal security review was completed in June 2026: 39 findings, all critical and high severity resolved. The summary is available on request. We do not present it as a substitute for an independent test.
GDPR
A data processing agreement is available on request. The architecture supports regional pinning and self-hosting, which is the usual route to residency requirements.

If a certification is a hard requirement for your procurement process today, tell us early and we will say plainly whether we can meet it rather than take you through an evaluation that cannot close.

Documents

Request the detailed documentation.

These are shared under mutual non-disclosure. Tell us which you need and we will send them, usually the same working day.

Documents

This opens your mail client with the request filled in, so nothing is submitted to a third party from this page.

Your mail client should have opened with the request ready to send. If it did not, write to security@spectis.io with the documents you need.

Security contact

Write to security@spectis.io for anything on this page, including subprocessor change notices.

Reporting a vulnerability

Send it to the address above with enough detail to reproduce. We acknowledge within two working days, keep you updated while we fix it, and credit you when it is resolved unless you would rather we did not. We will not pursue legal action over good-faith research that respects customer data.

Incidents

Affected customers are notified directly, with what happened, what was reached and what we changed. Contractual notification timelines are set in the agreement.