Skip to content
Spekir

01TRUST AND SECURITY

Security posture — facts only.

This page describes where your data is stored, who processes it, and what security controls are in place. No marketing, no certifications we have not earned.

Last updated: 2026-09-11

02

Compliance posture

Spekir is built toward SOC 2 Type 1 readiness. Evidence collection is scaffolded and controls are being implemented. We are not currently certified.

GDPR: We operate as a data processor under GDPR. Processor obligations are met. A Data Processing Agreement (DPA) is available on request.

Certification status and target dates
StandardStatusTarget date
SOC 2 Type IPlannedControls documented. Readiness work in progress.Q3 2026Planned
SOC 2 Type IIOn roadmap12-month observation period starts after Type I.Q1 2027Planned
ISO 27001On roadmapISMS gap analysis planned after SOC 2 Type I milestone.Q3 2027Planned

03

Hosting & data residency

Hosting and data residency facts
Application hostingVercel — Frankfurt, EU (eu-central-1 / fra1)
DatabaseNeon PostgreSQL — Frankfurt, EU (eu-central-1)
Data at restAll customer data stored in EU regions. No customer data leaves the EU at rest.
Build secretsStored in Vercel environment variables — never in source code
CDN edge nodesVercel Edge Network — requests served from nearest PoP, data pinned to Frankfurt

04

Authentication

Authentication facts
ProviderNextAuth v5 — self-hosted, no third-party identity broker
MethodsEmail + password (bcrypt hashed), Google OAuth
SessionsStored in Neon PostgreSQL (same EU region). JWT-signed server sessions.
2FA / MFATOTP-based 2FA available in Settings → Security
SSO / SAMLQ4 2026Planned
SCIM provisioningPlanned Q4 2026Planned

05

Encryption

Encryption facts
In transitTLS 1.3 enforced on all endpoints. HSTS enabled with 1-year max-age.
At restAES-256 managed by Neon (transparent encryption at storage layer). BYOK targeted Q3 2026.BYOK planned
Secrets & API keysVercel environment variables — injected at build time, never stored in git or logs
User API keysHashed with bcrypt before storage. Raw key shown once at creation only.

06

Backups & data retention

Backup and data retention facts
Automated backupsNeon point-in-time recovery — 7 days, on every branch and every workspace
Self-serve exportWorkspace data export (JSON + CSV) available from Settings → Trust Dashboard
Deletion on requestWorkspace data deleted within 30 days of verified deletion request
Audit log retention12 months, append-only. No deletion from application code.
Backup drillRestore drill run quarterly against Neon child branch (not production). Evidence committed internally.

07

Subprocessors

The following third parties process data on our behalf. We review subprocessors regularly and notify customers of material changes.

Sub-processors, purpose, region and DPA
ProcessorPurposeRegionDPA
VercelApplication hosting and CDNEU (Frankfurt eu-central-1)DPA ↗
NeonPostgreSQL database hostingEU (Frankfurt eu-central-1)DPA ↗
AnthropicAI model inference (Claude)Zero data retention configured. Opt-out of model training enforced via API agreement.US (no EU region available)DPA ↗
ResendTransactional email deliveryUS / EUDPA ↗
StripePayment processingEU (Ireland)DPA ↗
LangfuseAI observability and tracingEU (Frankfurt) — self-hostedInternal
InngestBackground job orchestrationUS (no EU region)DPA ↗

Need a DPA? Email hello@spekir.com — we will send the agreement within two working days.

08

Platform status

Platform status facts
Status pageTargeted Q3 2026 at status.spekir.comPlanned
Uptime target99.5% monthly. Measured, not contractually guaranteed during Early Access.
Incident notificationWorkspace admins notified within 24h of confirmed incident. GDPR Art. 33 notification within 72h.
Vulnerability reportsEmail security@spekir.com — the full responsible-disclosure policy is on the Security page

09

Topic deep-dives

Security

TLS 1.3, AES-256 at rest, NextAuth v5, audit logs, and rate limits.

Security

Compliance

GDPR posture, EU AI Act roadmap, and SOC 2 progress.

Compliance

Data handling

How your data flows — from ingest through deletion.

Data handling

Incidents

Full history. No reported security incidents to date.

Incidents

Subprocessors

Vercel, Neon, Anthropic, and Resend — with regions and DPA links.

Subprocessors

Data residency

Where your data lives — Frankfurt-first, tri-state residency policy, AI compute location, and sub-processor details.

Data residency

AI data handling

How Atlas uses AI with your portfolio — what flows to AI providers, what doesn't, retention facts, and customer controls.

AI data handling

10

Contact

Security questions

For questions about our security posture, DPA requests, or data residency.

hello@spekir.com

Responsible disclosure

Found a vulnerability? See our disclosure policy and safe harbour clause.

Read the security policy