Security, privacy, and responsible AI, by design. Sparko holds people's personal data, contracts, and financial records, so this page says what is implemented today, what is aligned to a framework, and what is still on the roadmap.
Three statuses, used consistently. Implemented means it is in the product or the infrastructure today. Aligned means our practices follow the framework and we make no certification claim. Roadmap means it is planned and not yet done.
| Area | Status | What that means |
|---|---|---|
| Encryption at rest | Implemented | AES-256, with sensitive fields under a per-customer key wrapped by AWS KMS |
| Encryption in transit | Implemented | TLS 1.2 or higher; HTTPS enforced on every endpoint |
| Hosting and data location | Implemented | AWS Singapore (ap-southeast-1), replicated across availability zones |
| Identity and access | Implemented | SSO (SAML 2.0, Okta, Entra), MFA (TOTP), passkeys, role-based access with field-level permissions, on every plan |
| Audit logging | Implemented | Authentication events, before and after change tracking, and every approved AI action with its outcome |
| Backups | Implemented | Automated, 35 days of retention, multi-AZ |
| Restore drill to a measured RTO and RPO | Roadmap | Scheduled ahead of the first enterprise engagement |
| Vulnerability scanning | Implemented | Dependency, static analysis, and container scans on every change to the main branch and weekly, plus automated dependency updates |
| Third-party penetration test | Roadmap | Planned ahead of the first enterprise engagement |
| Incident response | Implemented | Documented, severity-tiered process; initial customer notification within 48 hours of a confirmed data breach |
| Responsible AI | Implemented | Human approval before any automated action; customer data never used to train models |
| GDPR | Aligned | Processor obligations, DPA with Standard Contractual Clauses (Module Two); customers remain controllers |
| PDPA (Singapore) | Implemented | Applies to Sparko; a Data Protection Officer is designated |
| SOC 2 | Roadmap | SOC 2-aligned controls in place; no attestation yet |
| ISO/IEC 27001 | Roadmap | Controls mapped; certification pursued on customer demand |
Sparko is operated by Sparko Technologies Pte. Ltd., a private company limited by shares incorporated in Singapore on 15 September 2026 (UEN 202642599C). Your contract, our legal jurisdiction, and the region your data is stored in are all Singapore.
The Singapore Personal Data Protection Act (PDPA) applies to us, and our Data Protection Officer is reachable at [email protected]. See the Privacy Policy and DPA.
Sparko is hosted on AWS in Singapore (ap-southeast-1), with data replicated across multiple availability zones within that region. Customer data stays in the region in normal operation.
All data is encrypted at rest with AES-256. Sensitive fields such as salary and personal details carry an additional layer of field-level encryption under a key that belongs to your workspace, wrapped by AWS KMS. Uploaded files, including résumés, documents, and payslips, are encrypted at rest. Every connection uses TLS 1.2 or higher, with HTTPS enforced on every endpoint.
Role-based permissions define who can see and do what, down to individual fields and actions, with custom roles and department-based access. Single sign-on (SAML 2.0, Okta, Entra), multi-factor authentication (TOTP), and passkeys (WebAuthn) are included from the Core plan up, alongside password policy enforcement and session timeout controls.
A security audit trail records authentication activity, login history, and before and after values for data changes. Approving an AI action records its type, parameters, approving user, and outcome, including failures, to the same log, which admins can query and export on every plan.
Automated backups run continuously with 35 days of retention and multi-AZ replication for high availability.
A restore has not yet been drilled to a measured RTO and RPO. That runs ahead of our first enterprise engagement, alongside the penetration test.
Every change to the main branch is scanned, and the scans run again weekly: dependency audits, static analysis for security issues, and container image scanning, plus automated dependency updates.
A third-party penetration test is planned ahead of our first enterprise engagements.
We maintain a documented, severity-tiered incident response process with defined escalation paths and a post-incident review for every event, so lessons get fixed into the process.
For a confirmed data breach affecting your data, we send an initial notification within 48 hours of detection, ahead of the 72-hour window your own GDPR obligations may carry.
We use a small, named set of subprocessors: infrastructure hosting and backups (AWS), AI processing (Anthropic), content delivery (Cloudflare), and payment processing (Polar, acting as Merchant of Record, which is the seller of record for your transaction and handles the sales tax, VAT, or GST that applies where you are).
The full list with purpose and role, and our 30-day notice commitment for changes, is in the Data Processing Agreement.
Sparko never trains AI models on your data, and no customer's data is used to improve results for another. Résumé parsing and AI screening strip names and contact details before any prompt is sent, so screening evaluates an anonymised profile. The Ask Sparko assistant works from employee IDs and permission-scoped records rather than names, and only sees what the asking user is already allowed to see. Every AI-proposed action waits for a person's approval, and each tool re-checks its permission at the moment it runs.
How each class of AI is governed is on the Responsible AI page.
Unprogressed candidate résumés follow a 12-month retention policy. Data subject requests are fulfilled on every plan; retention policies and the request queue are managed in the product on the Business plan and above.
The full retention schedule by data category is in the Privacy Policy and DPA.
We run SOC 2-aligned controls and map them to ISO/IEC 27001, and we hold neither attestation nor certification yet. We are building the controls and the evidence first, and will pursue formal assurance based on customer demand.
Roadmap items on this page are roadmap items. None of them is a certification, an attestation, or a legal determination.
Report a suspected vulnerability to [email protected]. Tell us what you found and how to reproduce it; we acknowledge every report and keep you updated as we work on it.
We support good-faith research that respects customer data and avoids privacy violations, service disruption, or data destruction. Machine-readable contact details are at /.well-known/security.txt.
We walk through our practices in detail, including the roadmap items named above and where they sit in our plans.