SPUR·Innovation

Trust Center

How SPUR protects your data — our security practices, compliance posture, Canadian data sovereignty, the subprocessors we rely on, and how to report a security issue. We publish our status honestly, including what is still in progress.

SOC 2 Type II and ISO 27001:2022 programs are  in progress — engineered to the controls, formal certification not yet held.

Compliance & standardsWhere we stand — stated plainly

SPUR operates its infrastructure and its internal management system (CSuite) aligned to the frameworks below. We do not yet hold formal certification; certification is sequenced after our 2026 ISMS rollout. Control-by-control mapping and evidence packets are available to customers and auditors under NDA.

FrameworkStatusWhat it means today
SOC 2 Type IIIn progressTrust-services controls mapped to live audit evidence in CSuite; readiness engagement underway with an external firm. One-click evidence packets for any date range.
ISO/IEC 27001:2022In progressAnnex A used as the control library; Statement of Applicability maintained; ISMS rollout on the 2026 schedule.
PCI DSS v4.0 (SAQ-A)ScopedPayments run through Stripe (PCI Level 1). SPUR never stores, processes, or transmits card numbers; we own segmentation, access, and logging controls.
PIPEDA / Québec Law 25AlignedCanadian privacy law compliant by default; data stays in Canada with no US Cloud Act exposure.

Data sovereigntyCanadian by design

SPUR is a Canadian-owned company running on Canadian-owned infrastructure in Canadian data centres. Customer data is not subject to the US Cloud Act, and we do not resell it or use it to train third-party models.

Sovereign infrastructure

Compute and storage on SPUR-owned hardware in Canada — not rented US hyperscaler capacity.

Data residency

Customer data is stored and processed in Canada by default.

No Cloud Act exposure

A Canadian company on Canadian soil — outside US extraterritorial data-access regimes.

Security practicesHow we protect data

Encryption

TLS 1.2+ in transit with HSTS; secrets and sensitive stores encrypted at rest.

Access control

Multi-factor authentication enforced on privileged accounts; least-privilege, role-based access.

Continuous monitoring

Automated control checks run continuously and flag drift; security alerting on our fleet.

Backups & recovery

Regular backups with tested restores and documented recovery procedures.

Logging & audit trail

Operational mutations are logged and mapped to compliance controls; retention enforced.

Incident response

A documented IR plan with named on-call owners and defined escalation.

Hardening we apply across our public services: HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, and a strict Referrer-Policy.

SubprocessorsThird parties we rely on

We keep our external dependencies minimal. The providers below may process limited operational data on our behalf; each is bound by its own security and privacy commitments.

ProviderPurposeData
StripePayment processingBilling details, card data (held by Stripe, never by SPUR)
CloudflareDNS & edge protection for select public sitesRequest metadata (no customer content stored)
TailscalePrivate administrative networkingDevice identity / connection metadata
Overflow GPU providersBurst compute capacity (customer-optional)Only workloads a customer explicitly sends to overflow

A current, detailed subprocessor list is available to customers under NDA. We notify customers of material changes.

Vulnerability disclosureFound a security issue? Tell us.

We welcome good-faith reports from security researchers and treat them as a priority. Please give us a reasonable chance to remediate before any public disclosure.

How to report

Email [email protected]. Include the affected asset, reproduction steps, and impact. See our security.txt.

Our commitment

We acknowledge reports within 3 business days, keep you updated on remediation, and credit reporters who wish it.

Safe harbor

Good-faith research conducted per this policy will not lead to legal action from SPUR. Don't access others' data, degrade service, or run destructive tests.

Documentation & contactNeed our controls or a DPA?

Auditor-ready control mapping, evidence packets, our subprocessor list, and a Data Processing Agreement are available to customers and auditors under NDA. We respond to compliance and privacy requests same-day where possible.

Request controls documentation Email [email protected]