01Security
Designed for CISO approval
Spekir Atlas is built so security approval becomes the easiest part of the implementation, not the hardest.
AI inference runs via Anthropic Claude (US region) by default, under Standard Contractual Clauses and a zero-retention agreement — prompts and outputs are not retained after the API response. EU-only inference is available on request via an EU-region provider or your own keys (BYOK). Details on data residency
02
Clear data boundaries
Every table is workspace-scoped and every query is enforced at the data-access layer, in EU-hosted PostgreSQL. Database-level row-level security is in staged rollout. Your data never mingles with another customer's.
Verifiable controls
Every control is observable without asking us: TLS grades, audit logs, session lists, BYOK fingerprints. Eight specific tests a CISO can run in 30 minutes.
Customer-controlled AI
BYOK lets your workspace send AI requests through your own Anthropic tenant. Fail-closed by default: if your key is invalid, we do not silently fall back to our credentials.
03
Quick facts
| Data residency | EU (Frankfurt) — Neon PostgreSQL, Vercel fra1/cdg1 |
| Encryption at rest | AES-256 (Neon managed). BYOK on roadmap (Q3 2026) |
| Encryption in transit | TLS 1.3 enforced. HSTS enabled |
| Authentication | Email + password, Google OAuth. SSO/SAML planned Q4 2026 |
| SCIM provisioning | Planned Q4 2026 |
| BYOK (customer keys) | Anthropic provider supported now. Azure/Bedrock planned |
| Audit log retention | 12 months. Append-only, no delete from app code |
| Uptime target | 99.5% monthly. Status at status.spekir.com |
| Breach notification | 24h to affected workspace admins, 72h per GDPR Art. 33 |
| Workspace isolation | Workspace-scoped isolation enforced at the data-access layer on every table; database-level row-level security in staged rollout |
04
What you can verify yourself
- 01HTTPS everywhere — check TLS configuration via ssllabs.com/ssltest on spekir.com
- 02HSTS and security headers — verify with securityheaders.com
- 03EU data residency — request DPA and verify data processing location
- 04No cross-workspace data access — confirmed by penetration test report on request
- 05Audit log completeness — export your workspace audit log from Settings > Security
- 06User session list — view and revoke active sessions from your account settings
- 07BYOK key fingerprint — verify last 4 chars of SHA-256 match your key after adding
- 08Sub-processor changes — subscribe to RSS feed at /subprocessors/feed.xml
05
Documents
Security Architecture v1.0
Full technical architecture, data flows, controls, and incident response.
DPA Template
EU-compliant Data Processing Agreement template. Requires legal review before first signature.
Sub-processor List
Current list of all sub-processors with regions and functions.
Incident Response Policy
Severity classification, response timelines, breach notification procedure.
CAIQ-Lite Self-assessment
Cloud Security Alliance questionnaire responses.
PDFs are being finalized. Contact security@spekir.com to receive documents before public availability.
06
Certifications roadmap
We are pre-certification. We say this openly because honesty about our maturity level is more valuable than a roadmap badge.
SOC 2 Type I
Q3 2026
Controls documented. Readiness work in progress.
SOC 2 Type II
Q1 2027
12-month observation period starts after Type I.
ISO 27001
Q3 2027
ISMS gap analysis planned after SOC 2 Type I milestone.
07