Trust center

Trust and service levels

  • Uptime target 99.5% monthly per customer tenant
  • P1 response First response within 4 business hours
  • Support window Business days 09:00–17:00 CET · hello@spot-suite.com
  • Incidents Email notification to affected customers with a post-incident summary
  • Maintenance Announced in advance · most updates deploy without downtime
  • Contractual SLA Available for enterprise agreements on request

Subprocessors

  • Cloudflare Edge hosting and compute (Workers) on Cloudflare’s global network · files and evidence packs (R2) in Western Europe, not pinned to an EU jurisdiction · hourly database backup storage (object storage in Western Europe, not EU jurisdiction)
  • Supabase EU (Paris, on AWS) · Postgres database for customer data · daily backups
  • Microsoft 365 Email through Microsoft Graph · region not pinned by us
  • Google Fonts Typefaces in the app and emails · receives IP address · region not pinned by us
  • Microsoft Azure Only for workspaces bought through Azure Marketplace · in the Azure region the buyer picks at purchase: North Europe, West Europe or a US region
  • Changes Customers are notified in advance before any subprocessor change

Posture, disclosure, and paperwork

  • EU data storage by default

    Customer data from website signups is stored in the European Union on every plan, under Spot Cloud B.V., registered in the Netherlands (Cloud Horizons is EU-only for website signup; Azure Marketplace buyers pick their Azure region). Transfers outside the EU/EEA happen only on the customer’s written instruction. Exceptions: evidence and cost-pack files (R2) and the hourly backup dump sit in Cloudflare object storage in Western Europe under Cloudflare default jurisdiction, not its EU jurisdiction.

  • Compliance posture

    Platform controls are mapped to GDPR, DORA, and NIS2 for billing data handling. Formal certifications are not claimed — control mapping and audit evidence are shared under NDA.

  • Identity and provisioning

    Spot Suite OIDC with Microsoft Entra; passkeys and authenticator-app MFA are available and each user can turn them on; we do not require them. SCIM provisioning is on the enterprise roadmap, prioritized with design partners.

  • Vulnerability disclosure

    Report security issues to hello@spot-suite.com. Reports are acknowledged within two business days and disclosure is coordinated with the reporter. A machine-readable policy lives at /.well-known/security.txt.

  • Security questionnaires

    SIG- and CAIQ-style vendor questionnaire answers, the DPA, and control mapping are available on request, with a typical turnaround of two business days.

  • Backups and continuity

    Customer data lives in the shared EU Supabase Postgres project. Supabase backs it up once a day and keeps each backup for seven days, with no point-in-time restore; Supabase and Cloudflare both encrypt stored data by default. We also run our own hourly dump of that data into Cloudflare object storage in Western Europe. There is no failover to a second region, no restore drill has run yet, and restoring is a manual process, so we publish no recovery time or recovery point target. If every hourly dump succeeds and can be restored, an incident would lose roughly the last hour of data; that is an untested estimate, not a guarantee.

Running a vendor security review?

Get the DPA, control mapping, or questionnaire answers — typical turnaround two business days.