SPUR Innovation SPUR Innovation
ENGINEERED TO ENTERPRISE COMPLIANCE

Standards.
Engineered to.
Honestly mapped.

SPUR is engineered, built, and operated to internationally recognized security, privacy, and operational standards. We separate what we have built to from what we are formally certified for, because customers and regulators deserve that distinction in writing.

SPUR data centre interior
Posture summary

What SPUR is built to today.

Formal certification is sequenced after the 2026 ISMS rollout. Until then, status is published as engineered-to with control-by-control evidence available under NDA.

Certified Engineered to / aligned Adopted internally
StandardScope at SPURStatus
SOC 2 Type II Trust services criteria for security, availability, confidentiality, and privacy across SPUR-hosted services - CSuite, client containers, GPU compute, mail. Engineered to
ISO/IEC 27001:2022 Information security management system (ISMS) covering data centres, GPU fleet, and the SPUR client-template platform. Engineered to
PCI-DSS v4.0 Cardholder data handling for any SPUR-operated service that touches payment flows. Stripe is the primary processor; SPUR retains responsibility for segmentation, access, and logging. Engineered to
NIST SP 800-53 / CSF 2.0 Reference framework for control selection on the data-centre side and for federal and public-sector engagements. Engineered to
CIS Critical Security Controls v8 Tactical baseline for endpoint, server, and network hardening across the SPUR fleet. Implementation Group 2 (IG2) is the floor. Adopted internally
PIPEDA Canadian personal data residency by default. All workloads and storage inside Canadian jurisdiction; no cross-border data transfers. By design
Sovereignty

Your data stays in Canada. By design.

SPUR Compute and the SPUR Innovation Centre operate end-to-end inside Canadian jurisdiction. No US CLOUD Act exposure. No cross-border data transfers. PIPEDA-compliant by default, with sector-specific controls available for healthcare, financial services, legal, and public-sector tenants. Where the workload requires it, dedicated GPU capacity with no multi-tenancy is available.

  • Canadian-operated infrastructure, Canadian staff, Canadian governance
  • No CLOUD Act exposure
  • PIPEDA-compliant by default; HIPAA / SOC 2 / ISO 27001 controls available
  • Dedicated GPU option for regulated workloads
SPUR generator hall
SOC 2 Type II

Trust services criteria, mapped to live events.

SPUR's internal management system (CSuite) maps every operational mutation it logs to a SOC 2 trust-services control through a curated catalogue of audit-event glob patterns. The mapping covers the most material SOC 2 controls. Evidence packets (PDF + CSV) for any date range are generated by an admin in a single click and can be handed to an auditor as-is.

  • CC1.x - integrity, ethics, personnel competence
  • CC6.x - logical access, authentication, encryption in transit and at rest
  • CC7.x - vulnerability detection, anomaly response, incident response
  • CC8.x and CC9.x - change management, risk, and vendor lifecycle
See the full control matrix ->
SPUR data centre racks
PCI-DSS v4.0

Stripe holds the PAN. SPUR holds everything else.

SPUR uses Stripe as the primary processor; SPUR systems do not store, process, or transmit primary account numbers (PAN) directly. Stripe carries PAN responsibility under their PCI Level 1 attestation. SPUR retains responsibility for network segmentation, access controls, logging, and supporting policy - all mapped to PCI controls 1, 2, 4, 7, 8, 10, 11, and 12.

SPUR data centre
ISO/IEC 27001:2022

Annex A controls as the library.

SPUR's information security management system treats Annex A as the control library. The most material controls (A.5.1, A.5.15, A.5.18, A.5.30, A.6.3, A.8.2, A.8.5, A.8.16, A.8.24, A.8.28) are mapped to live audit-event evidence. Full Annex A inventory is maintained in CSuite and available under NDA. Formal certification is on the 2026 ISMS rollout schedule.

SPUR generator hall
Operational practice

Backup. Monitoring. Restore-tested.

Standards on paper are easy. SPUR's operational practice is what produces the evidence. Every host on the fleet is backed up to off-host storage with a tiered local + remote scheme. Restore is tested weekly, not just executed. Monitoring runs every minute across the GPU fleet, data centres, and the application platform. The audit_events table is the immutable system-of-record.

  • Daily 2-tier backup (local NVMe + off-host) with restore tests weekly
  • 1-minute watchdog across all hosts; cross-site failover validated
  • Continuous vulnerability scans across ports, TLS, headers, and mail posture
  • Immutable audit log for every operational mutation
SPUR data centre live

Need the control matrix?

Auditor-ready control mapping and evidence packets are available under NDA. We respond same-day to compliance requests.

Request controls documentation -> Full standards page Compute posture