Security & Trust
Built to protect data — including yours.
SpectGrid is a security product, so how we handle data matters as much as what we detect. Here's our model, stated plainly.
Data handling
The sensitive value never leaves the machine
Local-first detection
Scanning runs in the browser extension, on the device. Document text is extracted and scanned locally too — files aren’t uploaded to be scanned.
Redacted telemetry only
We store a redacted snippet and the policy outcome — enough to see and audit, never the raw secret or credential.
Per-tenant isolation
Each customer’s data is isolated at the database level (row-level security), so one tenant can never see another’s.
Configurable retention
Customers control how long event data is retained, within policy limits.
Compliance
Where we are — and where we're going
We'd rather show a roadmap than a wall of badges we haven't earned.
Compliance roadmap
- SOC 2 — planned. We’re building toward a formal audit; this page will reflect status honestly as it progresses.
- Data processing — a DPA and sub-processor list will be published alongside enterprise onboarding.
This roadmap is intentionally not a certification claim. Nothing here asserts a certification we don’t hold.
Questions about our security model?
Bring them to a demo — we'll walk through the data flow in detail.