/SLASHLOGIXX TRUST
Trust Center

How we keep your product, your data, and your customers safe.

SlashLogixx operates the Spark platform and every product built on it. This Trust Center is our public posture — the policies we run by, the controls we keep, the people we hold accountable, and the evidence we will hand to your security team on request.

AES-256
Data at rest
TLS 1.3
Data in transit
KMS
Managed encryption keys
US
Data residency, hosted tiers
Operating Policies

The full set, public.

Every Spark customer can read every policy we run by. Nothing here is paywalled, gated, or under NDA. If a procurement team asks for the underlying document, link them straight to the page.

Access Control

Who can touch what: identity, MFA, least-privilege, role boundaries, key rotation, and revocation on departure.

Read policy →

Incident Response

How we detect, contain, eradicate, recover, and notify when something goes wrong — and the clock we hold ourselves to.

Read policy →

Business Continuity & DR

Backup cadence, restore objectives, failover, tabletop frequency, and the playbook when the primary site goes dark.

Read policy →

Data Classification

How we label data — Public, Internal, Confidential, Restricted — and what handling each tier requires.

Read policy →

Vendor Management

How third parties earn the right to touch customer data: review, contractual posture, monitoring, and offboarding.

Read policy →

Privacy

What personal data we collect, why, where it lives, how long we keep it, and the rights every individual has.

Read policy →

Subprocessors

The complete list of every external service that touches customer data, what it does, and where it operates.

Read list →

Compliance & Frameworks

Our stance on SOC 2, ISO 27001, HIPAA, and other frameworks — what we map to today and how we provide evidence.

Read policy →

Encrypted in transit and at rest, on infrastructure we run in the United States.

The SlashLogixx-hosted Spark control plane runs on AWS in the US with daily encrypted backups and a target recovery time of four hours. On Spark Connect and Spark Connect BYOK, customer data lives in the customer's own VPC — and on Connect BYOK prompts go to the customer's own LLM endpoint — so the customer operates and secures those components directly.

See the tier matrix
Compliance Posture

Where we map to today.

We share an honest snapshot rather than a marketing badge. If a control is in place we'll show evidence. If a framework is on our roadmap rather than in our wallet, we say so plainly.

GDPR / UK GDPR
Operating posture
CCPA / CPRA
Operating posture
HIPAA
Eligible on signed BAA
PCI DSS
Out of scope — no card data stored
SOC 2 / ISO 27001
No formal audit — see Compliance