Privacy Policy
Effective date · 1 January 2026 · Last updated · August 2026
We collect only what we need to operate the service, we do not sell your data, and we give you control over what we hold.
1. What We Collect
Account information
When you sign up, we collect your name, work email address, and organization name.
Infrastructure metadata
SecureSpect reads metadata from your AWS account and GitHub organization via read-only integrations. We collect only the minimum data required to evaluate each SOC 2 control. We do not read your code, application data, customer records, or any data stored in your services.
Usage data
We collect standard application logs including which features you use, page visits, and error events. This data is used to improve the product and diagnose issues.
2. How We Use Your Data
- To provide and improve the SecureSpect service
- To communicate with you about your account, security issues, and product updates
- To generate compliance evidence and control test results visible only to your organization
- To diagnose bugs and improve reliability
We do not use your data to train machine learning models. We do not sell your data to third parties.
3. Data Isolation
All customer data is isolated at the database level using Postgres Row-Level Security policies. No organization can access another organization's data.
4. Data Retention
Evidence and control test results are retained for the duration of your subscription plus 90 days after account closure, after which they are deleted.
5. Your Rights
You may request a copy of your data, request deletion, or request correction by emailing support@securespect.com. We will respond within 30 days.
6. Cookies
The marketing website uses only essential cookies required for session management. We do not use advertising trackers or third-party analytics cookies on this page.
7. Contact
Questions about this policy: support@securespect.com