Your backlog is your roadmap. Here is exactly how we hold it.
Every control below is either in place today or marked as not yet available. Nothing is implied. If you are running a vendor review, this page and the one-page summary should answer most of it.
We are not SOC 2 certified.
No audit window is booked and no report exists. We would rather you learn that here than after you have signed. What we can do today: complete your security questionnaire, sign a DPA, and walk you through the controls inventory below, which lists exactly what is in place and what is not.
Controls inventory
21 controls in place, 7 not yet available. Last reviewed 4 August 2026.
Encryption
Data is encrypted in transit and at rest, and integration credentials get a second layer.
- TLS 1.3 for all traffic between your browser and SprintHelm
- AES-256 encryption at rest for all stored data
- Jira OAuth tokens are separately encrypted with AES-256-GCM under a per-environment master key before they are written to the database
- Key custody moved to a managed KMS with automatic rotationNot yet available
Access control
Every record in the database is scoped to the account that owns it, enforced by the database itself.
- Row-level security on every application table, scoping each record to its owning account. Enforced in Postgres, not only in application code
- Audit tables are readable by their owner and writable only by the service role
- OAuth 2.0 sign-in (Google) and email/password, with short-lived session tokens rotated on sign-in
- Single sign-on (SSO / SAML 2.0)Not yet available
- Role-based access control within a shared account (admin / member)Not yet available
Data handling
Your backlog is your roadmap. We hold as little of it as possible, in the EU, and never train on it.
- All customer data is stored and processed in the EU
- On Free and Pro, backlog data is processed in memory and not persisted. It is cleared when your session ends
- We never use your backlog, tickets or simulation inputs to train any AI model
- Customer data deleted from production within 30 days of account deletion or written request
- Alternative data residency regions (US or other)Not yet available
Application security
Standard web hardening, applied by default rather than per-route.
- Content Security Policy with a per-request nonce in production
- Rate limiting on authenticated API routes
- Inbound payment webhooks verified by cryptographic signature before processing
- Independent penetration testingNot yet available
Payments
We never see your card details.
- All card data is handled by Stripe. SprintHelm never receives or stores card numbers
- PCI DSS compliance is carried by Stripe as the payment processor
Auditability
Billing and integration activity is recorded, with timestamps and outcomes.
- Every plan change, payment event and notification is written to an append-only billing audit log with actor, timestamp, before/after plan and result
- Jira connection and import activity is recorded per workspace connection
- Customer-facing audit log export and searchNot yet available
Compliance
GDPR today. SOC 2 is not done, and we say so.
- GDPR-compliant processing for EU users, with a Data Processing Agreement available on request
- Published sub-processor list, with 30 days' notice of material changes
- 72-hour breach notification to affected controllers
- We complete customer security questionnaires on request
- SOC 2 Type II certificationNot yet available
Sub-processors
Third parties that process customer data on our behalf. We give 30 days' notice of material changes.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication and file storage | EU (West Europe) |
| Vercel | Application hosting and edge network | Global CDN |
| Stripe | Payment processing and subscription billing | US / EU |
| Anthropic | AI summary and PRD extraction inference | United States |
| Resend | Transactional email delivery | United States |
| Atlassian | Jira backlog import, only when you connect a Jira site | Per your Atlassian site region |
Running a vendor review?
Send us your security questionnaire and we will complete it. We will also sign a DPA and answer anything this page does not cover, including the things we have not built.
Contact enterprise@sprinthelm.com