---
updatedAt: 2026-09-16T14:13:06.000Z
agentTools:
  projectIndex: https://spartera.readme.io/llms.txt
---

# Security & Compliance

### Security & Compliance

This page describes how Spartera is built and operated today. It is a
description of current practices, not a warranty or service
commitment. Your rights are set by the
[Marketplace Terms](https://marketplace.spartera.com/terms), which
provide the platform "as is" and "as available" (Section 10), and,
where Spartera processes personal data for you, by the
[Data Processing Addendum](https://spartera.com/dpa/).

#### Certification status

Spartera does not currently hold SOC 2, ISO 27001, or other
third-party security certifications. If you need a completed security
questionnaire, email <security@spartera.com>.

#### Architecture: raw data stays with the seller

Spartera does not store sellers' raw datasets, tables, or files, and
does not replicate or keep a copy of them. The seller's own systems
remain the system of record. Handling depends on the product type:

* **Calculations and data feeds:** Spartera sends the query logic to
  the seller's system, and only the computed result or the filtered
  rows come back.
* **Rendered visualizations:** Spartera retrieves the records needed
  to draw the chart, renders it in memory, and discards the records
  without writing them to storage. The number of records is capped by
  product configuration.
* **API data products:** responses from a seller's endpoint pass
  through Spartera so they can be authenticated, filtered, formatted,
  and metered on their way to the buyer.

Spartera does keep a defined set of items: listing previews, sample
previews (three records by default), analytics and data feed snapshots
a buyer has purchased (kept for that buyer's account only), the
transformation logic behind each product, and product metadata. The
complete list is in Section 9 of the Marketplace Terms.

Marketplace products may not contain personal data. See
[Legal & Compliance](main-page.md).

#### Infrastructure

* Hosted on Google Cloud Platform in the United States
* Application services run in containers on Google Cloud Run, with
  separate development, staging, and production environments
* Traffic encrypted in transit with TLS 1.2 or higher
* Data stored on Spartera systems is encrypted at rest using Google
  Cloud encryption
* Seller connection credentials are stored in Google Cloud Secret
  Manager and can be rotated or removed by the seller at any time

#### Authentication and access

* **People** sign in with Google or Microsoft single sign-on. Spartera
  does not store user passwords.
* **Programs** authenticate with API keys scoped to specific products
  or endpoints. See [API Keys](../api-reference/api-keys.md).
* **Seller connections** use credentials the seller supplies, which
  should be read-only. See
  [Connections](../analytics-platform/connections.md).
* Administrative access to production is limited to authorized
  personnel.

#### Application controls

* Input validation on API requests
* Rate limiting and usage metering on API traffic
* Buyers are charged only for successful requests
* Dependency updates and security patches applied as part of normal
  development

#### Sub-processors

Spartera uses Google Cloud (hosting, authentication, and AI-assisted
search and analytics), Stripe (payments and seller payouts), SMTP2GO
(transactional email), and HubSpot (customer relationship
management). The authoritative, current list is in Annex 3 of the
[Data Processing Addendum](https://spartera.com/dpa/).

#### Security incidents

If an incident affects personal data Spartera processes on a client's
behalf, the notification terms in Section 9 of the
[Data Processing Addendum](https://spartera.com/dpa/) apply. For
personal information Spartera controls, notification follows
applicable law, as described in the
[Privacy Policy](https://spartera.com/privacy/).

#### What sellers are responsible for

Sellers are responsible for the security, availability, and uptime of
their own databases, warehouses, and API endpoints, and for granting
Spartera only the access their products need. See
[IP Whitelisting](../backend-best-practices/ip-whitelisting.md) and
[Connection Permissions](../analytics-platform/connection-permissions-reference.md).

#### Recommendations for users

* Store API keys in a secrets manager, never in client-side code or
  source control
* Rotate API keys and connection credentials periodically, and revoke
  keys you no longer use
* Enable multi-factor authentication on the Google or Microsoft
  account you sign in with
* Report suspected security issues promptly

#### Reporting a security issue

Email <security@spartera.com> with a description of the issue and steps
to reproduce it.