Coming soon

Security and privacy

Security and privacy, engineered in, not bolted on.

Security and privacy built into the platform, not bolted on. Everything on this page describes what Sprint Track actually does today. Certifications we do not hold are named as such.

GDPR aligned DPA available Sub-processors published

Infrastructure and hosting

Multi-region, isolated, and tested under load.

Where Sprint Track runs and how the platform stays available.

Cloud provider
Cloudflare. The application, database, object storage, vector search, and job queues all run on the Cloudflare developer platform.
Hosting model
Cloudflare global network. Requests are served from the edge location nearest the user. We do not currently offer per-workspace region pinning.
Network security
Cloudflare DDoS protection and TLS termination on every public endpoint. HTTP is redirected to HTTPS.
Availability
We aim for high availability but do not publish an uptime SLA. Enterprise customers can agree service levels by contract.
Backup and recovery
Deletion is two-phase: a workspace or project is suspended with a recovery export and stays restorable for 30 days before permanent purge.
Security testing
Automated checks run on every change, covering configuration, contract, schema, and tenancy-isolation invariants. We do not currently commission an annual third-party penetration test.

Data encryption

Encrypted in transit. Encrypted at rest. Connector credentials sealed per workspace.

Every byte of customer data is encrypted on the wire and on disk.

Encryption in transit
TLS on every connection to Sprint Track and to every sub-processor.
Encryption at rest
Provided by the Cloudflare platform across the database, object storage, and vector store.
Connector credentials
Third-party tokens are stored under envelope encryption. Each entry has its own AES-GCM key wrapped by a versioned root key.
Scope binding
Each credential ciphertext is cryptographically bound to its workspace, purpose, provider, and owning record, so a stored credential cannot be replayed into another scope.
Token storage
Authentication tokens, OAuth client secrets, API tokens, and SCIM tokens are stored hashed, never in plain text.
Key rotation
Root keys are versioned. Rotation re-encrypts entries to the current key version without decrypting them into the clear.

Identity and access management

The controls your identity team expects, on day one.

SSO, SCIM, MFA, RBAC, and ABAC. No add-on tier required for the basics.

SSOEnterprise
SAML 2.0 and OIDC with domain verification. Implicit sign-up is disabled by default.
SCIM provisioningEnterprise
Automated provisioning and deprovisioning via SCIM 2.0, with group-to-role and attribute-to-role mapping. Tokens stored hashed.
Two-factor auth
TOTP with encrypted backup codes. Can be enforced for every member at workspace level.
Step-up verification
Sensitive actions require re-verification within a short validity window, separate from the sign-in session.
Role-based access
Roles composed from a permission catalogue and enforced server-side on every request, at workspace and project level.
Approval gates
Outbound writes to connected systems require a matching approval record, hash-checked against the approved payload. There is no unapproved write path.
Session management
Configurable session timeout and admin-forced session revocation.

Compliance and certifications

Ready for the frameworks your buyers ask about.

Active compliance posture and certifications either held or in active progress.

GDPR and UK GDPRReady
Data Processing Agreement published and in force on acceptance of our Terms. EU Standard Contractual Clauses and the UK International Data Transfer Addendum are incorporated for international transfers.
Sub-processorsReady
Full list published, with purpose, location, and data processed for each. At least 30 days notice before adding or replacing one.
US state privacyReady
CCPA and CPRA disclosures published. We do not sell personal information and do not share it for cross-context behavioural advertising.
SOC 2 and ISO 27001
Not certified. We do not hold a SOC 2 report or ISO 27001 certification, and we will say so here if that changes.
HIPAA
Not supported. Sprint Track is not designed for protected health information and we do not offer a Business Associate Agreement.
Data retention
Published retention and redaction periods per record type. Deleted workspaces stay recoverable for 30 days, then are permanently purged including stored files.

Audit logs and observability

Every action recorded. Every record immutable.

Built for finance, healthcare, and government teams that require defensible audit trails.

What is logged
Sign-in and sign-out, workspace changes, project creation and deletion, member invites and removals, permission changes, and canonical actions taken through the platform runtime.
Retention
Workspace audit logs are kept 90 days on standard plans and up to 12 months on Enterprise. IP address and user agent are redacted after 90 days on every plan.
Security events
Authentication, SSO, SCIM, and integration anomalies are recorded separately and kept for up to 13 months for investigation.
Administrator actions
Platform administrator access to customer environments is recorded in a separate audit trail kept for up to 24 months.
AI spend ledger
AI usage is recorded in an append-only, HMAC-chained ledger holding model, rate, and unit counts only. No prompt content and no model output.
Availability
Audit log access is available on Enterprise plans. Export can be requested at hello@sprintrack.com.

Vulnerability disclosure program

Found something? Tell us safely.

A responsible disclosure policy with a clear SLA, scope, and safe harbour.

Contact
hello@sprintrack.com. Please include enough detail for us to reproduce the issue.
Scope
Production systems, REST API, authentication flows, and the customer data plane. Out of scope: third-party services, social engineering, and physical attacks.
Response
We acknowledge reports as quickly as we can and keep reporters updated through triage and remediation. We do not currently publish a fixed response SLA.
Safe harbour
No legal action against good-faith researchers who follow this policy. We agree a coordinated disclosure timeline before publication.
Credit
We credit researchers publicly with their permission. We do not currently run a paid bug-bounty program.

Internal security controls

Security extends to how our own team operates.

The operational practices that sit behind the platform.

Least privilege
Personnel access is limited to what each role requires, and administrator access to customer environments is recorded in an audit trail.
Confidentiality
Everyone with access to customer data is bound by written confidentiality obligations.
Change review
Changes are reviewed before release, and automated checks enforce configuration, contract, and schema invariants in the build pipeline.
Vendor security
Sub-processors are assessed before engagement, bound by data protection terms no less protective than our own DPA, and published with 30 days change notice.

Sub-processors

Every third party that touches customer data.

Maintained per GDPR Article 28. The canonical list, with transfer safeguards for each entry, is published at sprintrack.com/sub-processors. We give at least 30 days notice before adding or replacing an entry.

We notify customers 30 days before adding or replacing a sub-processor.
Sub-processorPurposeLocationData processed
CloudflareApplication hosting, database, object storage, vector search, CDN and DDoS protectionGlobalAll customer workspace and application data
PaddlePayment processing and merchant of record for paid plansUS / EUBilling contact and payment data
BrevoTransactional email deliveryEUEmail addresses and message content
Google (Gemini API)AI feature inference (opt-in)USPrompts, grounding context and uploaded sources, only when AI features are enabled by the workspace admin
Google (OAuth)Sign in with Google, where a user chooses itUSEmail address, name and profile image
GitHubRepository and issue integration (opt-in)USRepository and issue data, only for workspaces that connect GitHub
OpenAISprint Track app inside ChatGPT (opt-in)USWorkspace, project and issue data returned to the connected user

Security documentation

Available on request, fast.

What procurement and InfoSec teams typically ask for. Our Data Processing Agreement, sub-processor list, and Privacy Policy are published in full and need no request. The rest we release under NDA.

All security documentation available on request
Most documents require an NDA. Procurement teams typically receive the full pack within two business days of request.

Data Processing Agreement

Published in full, in force on acceptance of our Terms. Countersigned copy on request.

Sub-processor list

Published in full, with a 30-day change-notification commitment.

Privacy Policy

Including retention schedule, international transfers, and AI data handling.

Security questionnaire

We complete customer security questionnaires on request.

Architecture overview

NDA

High-level system diagram covering data flow and trust boundaries.

Incident response summary

NDA

Summary of our incident response procedure and communication chain.

Incident response

What happens when something goes wrong.

The detection, classification, and communication chain customers can plan against.

Detection
Platform logging and traces, plus automated alerting on authentication, integration, and billing anomalies recorded as security events.
Classification
Four-tier severity scale: P0 (critical, customer data at risk) to P3 (informational).
Customer notification
We notify affected customers of a personal data breach without undue delay, and in time for controllers to meet their own 72-hour obligation under GDPR.
Who we contact
Notifications go to the workspace administrators on record. Keep administrator contact details current.
Review
Every customer-impacting incident gets an internal root-cause review, and we share the findings with affected customers on request.

Need anything we did not list?

Our security team replies fast. Request a specific document, ask a clarifying question, or check live status.