Trust center

Service level targets

  • Uptime target 99.5% monthly per customer environment
  • P1 response First response within 4 business hours
  • Support window Business days 09:00–17:00 CET · hello@spot-suite.com
  • Incidents Email notification to affected customers with a post-incident summary
  • Maintenance Announced in advance · most updates deploy without downtime
  • Contractual SLA Available for enterprise agreements on request

Subprocessors

  • Cloudflare Application hosting and compute (Workers) · encrypted key and credential storage (Workers KV) · hourly database backup storage (object storage in Western Europe, not EU jurisdiction)
  • Supabase EU (Paris, on AWS) · Postgres database for certificate records, settings, and audit events · daily backups
  • Microsoft 365 Email through Microsoft Graph · region not pinned by us
  • Google Fonts Typefaces in the app and emails · receives IP address · region not pinned by us
  • crt.sh and Cert Spotter Certificate Transparency search for the domains you monitor · region not pinned by us
  • Microsoft Azure Only for workspaces bought through Azure Marketplace · in the Azure region the buyer picks at purchase: North Europe, West Europe or a US region
  • Changes Customers are notified in advance before any subprocessor change

Posture, disclosure, and paperwork

  • EU data storage

    For website signups, certificate records, settings, and audit events are stored in the EU on every plan (Azure Marketplace workspaces excepted), under Spot Cloud B.V., registered in the Netherlands. There are three exceptions. Encrypted private keys and credentials are held in Cloudflare Workers KV, which is not limited to EU locations. Our hourly backup dump of the database is kept in Cloudflare object storage in Western Europe under Cloudflare's default jurisdiction, not its EU jurisdiction, so that copy is not covered by the EU storage commitment. Workspaces bought through Azure Marketplace are stored in the Azure region the buyer picks at purchase: North Europe, West Europe or a US region.

  • Compliance posture

    Posture is GDPR · DORA · NIS2. Control mapping and audit evidence are shared under NDA.

  • Identity and provisioning

    Spot Suite OIDC with Microsoft Entra ID, Okta, or any OIDC provider, with sign-in policy set by your identity provider. Spot Suite does not itself enforce MFA; each user can add a passkey or authenticator app. SAML and SCIM provisioning are on the enterprise roadmap, prioritized with design partners.

  • Vulnerability disclosure

    Report security issues to hello@spot-suite.com. Reports are acknowledged within two business days and disclosure is coordinated with the reporter. A machine-readable policy lives at /.well-known/security.txt.

  • Security questionnaires

    SIG- and CAIQ-style vendor questionnaire answers, the DPA, and control mapping are available on request, with a typical turnaround of two business days.

  • Database backups

    Certificate records, settings, and audit events live in the Supabase Postgres database. Supabase backs it up once a day and keeps each backup for seven days, with no point-in-time restore. We also run our own hourly dump of that database into Cloudflare object storage in Western Europe. There is no failover to a second region, we have not yet run a restore drill, and restoring is a manual process, so we publish no recovery time or recovery point target. If every hourly dump succeeds and can be restored, an incident would lose roughly the last hour of data; that is an estimate we have not yet tested, not a guarantee.

Running a vendor security review?

Get the DPA, control mapping, or questionnaire answers — typical turnaround two business days.