SprintHelm
Trust Center

Your backlog is your roadmap. Here is exactly how we hold it.

Every control below is either in place today or marked as not yet available. Nothing is implied. If you are running a vendor review, this page and the one-page summary should answer most of it.

We are not SOC 2 certified.

No audit window is booked and no report exists. We would rather you learn that here than after you have signed. What we can do today: complete your security questionnaire, sign a DPA, and walk you through the controls inventory below, which lists exactly what is in place and what is not.

Controls inventory

21 controls in place, 7 not yet available. Last reviewed 4 August 2026.

One-page summary

Encryption

Data is encrypted in transit and at rest, and integration credentials get a second layer.

  • TLS 1.3 for all traffic between your browser and SprintHelm
  • AES-256 encryption at rest for all stored data
  • Jira OAuth tokens are separately encrypted with AES-256-GCM under a per-environment master key before they are written to the database
  • Key custody moved to a managed KMS with automatic rotationNot yet available

Access control

Every record in the database is scoped to the account that owns it, enforced by the database itself.

  • Row-level security on every application table, scoping each record to its owning account. Enforced in Postgres, not only in application code
  • Audit tables are readable by their owner and writable only by the service role
  • OAuth 2.0 sign-in (Google) and email/password, with short-lived session tokens rotated on sign-in
  • Single sign-on (SSO / SAML 2.0)Not yet available
  • Role-based access control within a shared account (admin / member)Not yet available

Data handling

Your backlog is your roadmap. We hold as little of it as possible, in the EU, and never train on it.

  • All customer data is stored and processed in the EU
  • On Free and Pro, backlog data is processed in memory and not persisted. It is cleared when your session ends
  • We never use your backlog, tickets or simulation inputs to train any AI model
  • Customer data deleted from production within 30 days of account deletion or written request
  • Alternative data residency regions (US or other)Not yet available

Application security

Standard web hardening, applied by default rather than per-route.

  • Content Security Policy with a per-request nonce in production
  • Rate limiting on authenticated API routes
  • Inbound payment webhooks verified by cryptographic signature before processing
  • Independent penetration testingNot yet available

Payments

We never see your card details.

  • All card data is handled by Stripe. SprintHelm never receives or stores card numbers
  • PCI DSS compliance is carried by Stripe as the payment processor

Auditability

Billing and integration activity is recorded, with timestamps and outcomes.

  • Every plan change, payment event and notification is written to an append-only billing audit log with actor, timestamp, before/after plan and result
  • Jira connection and import activity is recorded per workspace connection
  • Customer-facing audit log export and searchNot yet available

Compliance

GDPR today. SOC 2 is not done, and we say so.

  • GDPR-compliant processing for EU users, with a Data Processing Agreement available on request
  • Published sub-processor list, with 30 days' notice of material changes
  • 72-hour breach notification to affected controllers
  • We complete customer security questionnaires on request
  • SOC 2 Type II certificationNot yet available

Sub-processors

Third parties that process customer data on our behalf. We give 30 days' notice of material changes.

ProviderPurposeLocation
SupabaseDatabase, authentication and file storageEU (West Europe)
VercelApplication hosting and edge networkGlobal CDN
StripePayment processing and subscription billingUS / EU
AnthropicAI summary and PRD extraction inferenceUnited States
ResendTransactional email deliveryUnited States
AtlassianJira backlog import, only when you connect a Jira sitePer your Atlassian site region

Running a vendor review?

Send us your security questionnaire and we will complete it. We will also sign a DPA and answer anything this page does not cover, including the things we have not built.

Contact enterprise@sprinthelm.com