How SPUR protects your data — our security practices, compliance posture, Canadian data sovereignty, the subprocessors we rely on, and how to report a security issue. We publish our status honestly, including what is still in progress.
SPUR operates its infrastructure and its internal management system (CSuite) aligned to the frameworks below. We do not yet hold formal certification; certification is sequenced after our 2026 ISMS rollout. Control-by-control mapping and evidence packets are available to customers and auditors under NDA.
| Framework | Status | What it means today |
|---|---|---|
| SOC 2 Type II | In progress | Trust-services controls mapped to live audit evidence in CSuite; readiness engagement underway with an external firm. One-click evidence packets for any date range. |
| ISO/IEC 27001:2022 | In progress | Annex A used as the control library; Statement of Applicability maintained; ISMS rollout on the 2026 schedule. |
| PCI DSS v4.0 (SAQ-A) | Scoped | Payments run through Stripe (PCI Level 1). SPUR never stores, processes, or transmits card numbers; we own segmentation, access, and logging controls. |
| PIPEDA / Québec Law 25 | Aligned | Canadian privacy law compliant by default; data stays in Canada with no US Cloud Act exposure. |
SPUR is a Canadian-owned company running on Canadian-owned infrastructure in Canadian data centres. Customer data is not subject to the US Cloud Act, and we do not resell it or use it to train third-party models.
Compute and storage on SPUR-owned hardware in Canada — not rented US hyperscaler capacity.
Customer data is stored and processed in Canada by default.
A Canadian company on Canadian soil — outside US extraterritorial data-access regimes.
TLS 1.2+ in transit with HSTS; secrets and sensitive stores encrypted at rest.
Multi-factor authentication enforced on privileged accounts; least-privilege, role-based access.
Automated control checks run continuously and flag drift; security alerting on our fleet.
Regular backups with tested restores and documented recovery procedures.
Operational mutations are logged and mapped to compliance controls; retention enforced.
A documented IR plan with named on-call owners and defined escalation.
Hardening we apply across our public services: HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, and a strict Referrer-Policy.
We keep our external dependencies minimal. The providers below may process limited operational data on our behalf; each is bound by its own security and privacy commitments.
| Provider | Purpose | Data |
|---|---|---|
| Stripe | Payment processing | Billing details, card data (held by Stripe, never by SPUR) |
| Cloudflare | DNS & edge protection for select public sites | Request metadata (no customer content stored) |
| Tailscale | Private administrative networking | Device identity / connection metadata |
| Overflow GPU providers | Burst compute capacity (customer-optional) | Only workloads a customer explicitly sends to overflow |
A current, detailed subprocessor list is available to customers under NDA. We notify customers of material changes.
We welcome good-faith reports from security researchers and treat them as a priority. Please give us a reasonable chance to remediate before any public disclosure.
Email [email protected]. Include the affected asset, reproduction steps, and impact. See our security.txt.
We acknowledge reports within 3 business days, keep you updated on remediation, and credit reporters who wish it.
Good-faith research conducted per this policy will not lead to legal action from SPUR. Don't access others' data, degrade service, or run destructive tests.
Auditor-ready control mapping, evidence packets, our subprocessor list, and a Data Processing Agreement are available to customers and auditors under NDA. We respond to compliance and privacy requests same-day where possible.
Request controls documentation Email [email protected]