Skip to main content

TRUST CENTER

Security and trust at Spiich.

Spiich is built for security and privacy from the ground up. Your data is encrypted, stored and processed in the EU, and never used to train AI models.

GDPR compliantEU hostedNo model trainingEncrypted end to end

Last updated June 28, 2026

How we protect your data

Security controls span encryption, access, infrastructure, and the way our AI handles your data.

Encryption

  • TLS 1.2 or higher required on all public endpoints
  • AES-256 encryption at rest for databases and object storage
  • Encryption keys managed in a dedicated secrets manager
  • Passwords hashed with bcrypt; OAuth tokens encrypted at rest

AI & data use

  • Customer content is never used to train or fine-tune AI models
  • Zero data retention terms with all language-model providers
  • AI inference runs in EU regions
  • External content read by agents is treated as untrusted input, with prompt-injection safeguards and schema-validated tool calls

Access control

  • CRM access is bounded by OAuth scopes an admin approves, with object and field-level locking
  • Least-privilege IAM with per-service identities and no shared root account
  • MFA enforced on all core internal systems
  • Integrations can be disconnected in one click, which clears stored tokens

Infrastructure

  • Built on managed, automatically patched cloud infrastructure
  • Per-tenant database schema isolation
  • Dual-region redundancy within the EU for storage and backups
  • Dependencies continuously monitored and scanned for vulnerabilities

Privacy & governance

  • GDPR-based Data Processing Agreement available on request
  • Data subject rights supported: access, erasure, and portability
  • EU-only data residency for customer production data
  • Defined retention with export and deletion available on request

Monitoring & resilience

  • Centralized logging and monitoring across our infrastructure, with alerting
  • AI and agent calls traced for observability and anomaly detection
  • Automated database backups with point-in-time recovery
  • Incident response with breach notification within 48 hours (GDPR Art. 33)

Data residency

All customer production data is stored and processed within the EU. The only exception is agent web search, which sends tenant-unattributed queries to US providers with zero data retention.

Application & database

Hosted and processed within the EU

AI inference

Runs within the EU

Backups & redundancy

Dual-region redundancy within the EU

Documentation

These documents are available to customers and prospects on request, under NDA. Reach out and we will share access promptly.

Data Processing Agreement (DPA)

Our standard GDPR data processing terms.

Request access ↗

Sub-processor list

Current sub-processors and what each one processes.

Request access ↗

CASA Tier 2 assessment

Cloud application security assessment (TAC Security, Nov 2025).

Request access ↗

OWASP baseline scan summary

Latest application security scan results.

Request access ↗

Architecture & data-flow overview

How data is stored, processed, and transferred.

Request access ↗

DORA addendum

For regulated financial institutions.

Request access ↗
Request all documents

Frequently asked questions

The questions we are asked most often in security reviews. Can't find what you need? Email hello@spiich.ai.

Data & privacy

All customer production data is stored and processed within the EU, with dual-region redundancy for resilience. The only exception is agent web search, which sends tenant-unattributed queries to US providers with zero data retention. We can share more detail on our EU infrastructure on request.
Yes. TLS 1.2 or higher is required on all public endpoints, and data is encrypted at rest with AES-256 across our database and object storage. Encryption keys are held in a dedicated secrets manager.
Yes. We operate under a GDPR-based Data Processing Agreement, store and process customer production data within the EU, and meet the Article 33 breach-notification obligation. Our privacy policy is public.
Customers can request deletion or export of recordings, transcripts, and associated data through support or the DPA process, and can disconnect any integration from the app at any time, which clears the related stored tokens.
Customer data is available for export for 30 days after termination. After that window it is deleted, except for copies in routine backups (purged on our standard 15-day cycle) and data we are legally required to retain.
No security incidents have occurred to date.

Hosting & infrastructure

Spiich is hosted entirely within the EU on managed, enterprise-grade cloud infrastructure. Details of our specific providers and architecture are available on request under NDA.
Yes. Each sub-processor is engaged under a Data Processing Agreement, predominantly EU-hosted, with zero-data-retention terms where applicable. Our complete, current sub-processor list is available on request under NDA.
Each customer has a dedicated database schema within a shared, managed PostgreSQL instance, with its own per-service IAM identity.
Automated database backups with 15-day retention and point-in-time recovery, deletion protection on the production database, and dual-region redundancy within the EU for storage and backups.

AI model use and safeguards

No. None of our model providers train, fine-tune, or improve their models on Spiich prompt or inference data, and our public terms confirm customer content is not used to train AI models. Inference runs under zero-data-retention terms in EU regions.
We work only with established enterprise AI providers that contractually commit to zero data retention and to never training on customer data, with all inference running in EU regions. The specific providers and terms are available on request under NDA.
All external content an agent reads, such as email, calendar invitations, and web pages, is treated as untrusted input. The system prompt instructs the agent to treat embedded directives as data rather than commands, tool-call responses are schema-validated, and a pre-write duplicate check guards against mass record creation.

Security & compliance

We hold a CASA Tier 2 certification (TAC Security, November 2025).
We run OWASP ZAP baseline scans (CASA Tier 2, TAC Security) against our backend and frontend, alongside ongoing internal security testing.
We support email and password, with passwords hashed using bcrypt, plus OAuth for connected integrations and short-lived access tokens that rotate frequently.
Incidents are handled by our CTO and senior engineering with defined roles for detection, containment, and recovery. Customers are notified of a confirmed personal-data breach without undue delay, and at most 48 hours after detection, per GDPR Article 33.
Access follows least privilege: per-service IAM roles with no shared root account, MFA on core internal systems, and human access to production limited to a small number of senior engineers for policy-compliance purposes.