Security

Isolation, encryption, and audit by default

  • Spot Suite OIDC SSO

    Operators sign in via Microsoft Entra with passkeys, TOTP MFA, and Entra ID federation. No shared passwords across Spot Suite products.

  • One shared application

    A single Cloudflare Worker serves every customer. Customer data sits in one Postgres database that Supabase, a subprocessor, hosts in the EU.

  • How customer data is separated

    On your own environment host (yourcompany.automate-certificates.com), certificate data is kept in a schema of its own. A request there that cannot be matched to a customer is refused; there is no fallback. Data created through app.automate-certificates.com or the API at api.automate-certificates.com, Azure agent scan results, and accounts, sign-in sessions, and API keys live in a shared central schema, where every query is filtered by organization.

  • EU data residency

    For website signups, customer environments run in the EU under Spot Cloud B.V. (Azure Marketplace workspaces excepted). Certificate inventory and audit records are stored in the EU, with three exceptions. Encrypted private keys and credentials are held in Cloudflare Workers KV, which is not limited to EU locations. Our hourly backup dump of the database is kept in Cloudflare object storage in Western Europe under Cloudflare's default jurisdiction, not its EU jurisdiction. Workspaces bought through Azure Marketplace are stored in the Azure region the buyer picks at purchase: North Europe, West Europe or a US region.

  • Private key encryption

    Private keys are encrypted with AES-256-GCM and stored apart from certificate records. The app decrypts a key in memory only to issue, renew, or deploy its certificate, or when an owner or admin exports it. Exports are recorded in the audit log.

  • Append-only audit logging

    Every issuance, deployment, and Marketplace lifecycle action is recorded with reviewer identity and timestamp. CSV export and webhook delivery.

  • Service principal authentication

    Azure tenant scans authenticate via a service principal with RS256 JWKS validation. Scoped API keys for programmatic access.

  • GDPR · DORA · NIS2

    Platform controls are mapped to GDPR, DORA, and NIS2. Audit evidence and the control-mapping pack are shared under NDA.

Security specifications.

  • Sign-in Spot Suite OIDC · Entra MFA · passkeys
  • Tenant scans Azure SP · RS256 JWKS validation
  • API access Scoped API keys · MCP tools
  • Encryption AES-256-GCM at rest
  • Infrastructure Shared Worker · Supabase Postgres (EU)
  • Residency EU · Spot Cloud B.V.
  • Audit Append-only · CSV · webhooks
  • Compliance GDPR · DORA · NIS2

Walk through the security model

Book a 30-minute demo covering tenant isolation, key encryption, and audit exports.