How Spectis handles your data.
This page is written for the person who has to sign off on us. It states what the software collects, what it stores, who can read it and where it runs, at the level of detail a security questionnaire asks for. Where something is not yet in place, it says so.
network hops added. Spectis observes; it never sits in the request path.
subprocessor for the managed service. None at all if you self-host.
tenant per instance, with its own database. No shared data plane.
prompts or completions captured from the coding-agent hook.
What leaves an endpoint.
By mode, so you can hold us to it. Each of these is enforced inside the scanner rather than promised by policy, and the same statement is rendered in the product on the integrations page.
What is stored
Who can read what.
Roles are enforced server-side on every request, and the separation is structural rather than a setting. The written contract behind this table is available on request.
| Role | Aggregates | Conversation content | Configuration |
|---|---|---|---|
| Compliance | Organisation-wide | Yes, and every read is auditedThe audit trail of those reads is itself confidential | No |
| Security | Organisation-wide | Only if the organisation grants itAn audited setting, off by default | Partial |
| Auditor | Organisation-wide, read-only | No | No |
| Manager | Their own reports onlyResolved fail-closed: if the reporting line cannot be established, nothing is returned | No | No |
| Administrator | NoneOperates the platform and cannot read who used which AI service | No | Yes |
A filter can only ever narrow what a role may already see. Naming a person outside your scope returns nothing and is indistinguishable from naming someone who does not exist, so the filter cannot be used to enumerate the directory.
Where it runs, and how it is protected.
One, for the managed service.
Most vendors in this category list twenty. We list one because the product is deliberately single-tenant and does almost nothing off-instance.
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Amazon Web Services | Application hosting, database, object storage, secrets, content delivery | All customer data held by the managed service | Region you select |
Where we actually are.
If a certification is a hard requirement for your procurement process today, tell us early and we will say plainly whether we can meet it rather than take you through an evaluation that cannot close.
Request the detailed documentation.
These are shared under mutual non-disclosure. Tell us which you need and we will send them, usually the same working day.
Security contact
Write to security@spectis.io for anything on this page, including subprocessor change notices.
Reporting a vulnerability
Send it to the address above with enough detail to reproduce. We acknowledge within two working days, keep you updated while we fix it, and credit you when it is resolved unless you would rather we did not. We will not pursue legal action over good-faith research that respects customer data.
Incidents
Affected customers are notified directly, with what happened, what was reached and what we changed. Contractual notification timelines are set in the agreement.