TRUST CENTER
Security and trust at Spiich.
Spiich is built for security and privacy from the ground up. Your data is encrypted, stored and processed in the EU, and never used to train AI models.
Last updated June 28, 2026
How we protect your data
Security controls span encryption, access, infrastructure, and the way our AI handles your data.
Encryption
- TLS 1.2 or higher required on all public endpoints
- AES-256 encryption at rest for databases and object storage
- Encryption keys managed in a dedicated secrets manager
- Passwords hashed with bcrypt; OAuth tokens encrypted at rest
AI & data use
- Customer content is never used to train or fine-tune AI models
- Zero data retention terms with all language-model providers
- AI inference runs in EU regions
- External content read by agents is treated as untrusted input, with prompt-injection safeguards and schema-validated tool calls
Access control
- CRM access is bounded by OAuth scopes an admin approves, with object and field-level locking
- Least-privilege IAM with per-service identities and no shared root account
- MFA enforced on all core internal systems
- Integrations can be disconnected in one click, which clears stored tokens
Infrastructure
- Built on managed, automatically patched cloud infrastructure
- Per-tenant database schema isolation
- Dual-region redundancy within the EU for storage and backups
- Dependencies continuously monitored and scanned for vulnerabilities
Privacy & governance
- GDPR-based Data Processing Agreement available on request
- Data subject rights supported: access, erasure, and portability
- EU-only data residency for customer production data
- Defined retention with export and deletion available on request
Monitoring & resilience
- Centralized logging and monitoring across our infrastructure, with alerting
- AI and agent calls traced for observability and anomaly detection
- Automated database backups with point-in-time recovery
- Incident response with breach notification within 48 hours (GDPR Art. 33)
Data residency
All customer production data is stored and processed within the EU. The only exception is agent web search, which sends tenant-unattributed queries to US providers with zero data retention.
Application & database
Hosted and processed within the EU
AI inference
Runs within the EU
Backups & redundancy
Dual-region redundancy within the EU
Documentation
These documents are available to customers and prospects on request, under NDA. Reach out and we will share access promptly.
Data Processing Agreement (DPA)
Our standard GDPR data processing terms.
Sub-processor list
Current sub-processors and what each one processes.
CASA Tier 2 assessment
Cloud application security assessment (TAC Security, Nov 2025).
OWASP baseline scan summary
Latest application security scan results.
Architecture & data-flow overview
How data is stored, processed, and transferred.
DORA addendum
For regulated financial institutions.
Frequently asked questions
The questions we are asked most often in security reviews. Can't find what you need? Email hello@spiich.ai.