SprintHelm — Security controls summary
Controls inventory
21 of 28 controls in place · 7 not yet available · Last reviewed 4 August 2026
Certification status: We are not SOC 2 certified.
No audit window is booked and no report exists. We would rather you learn that here than after you have signed. What we can do today: complete your security questionnaire, sign a DPA, and walk you through the controls inventory below, which lists exactly what is in place and what is not.
Encryption
Data is encrypted in transit and at rest, and integration credentials get a second layer.
| TLS 1.3 for all traffic between your browser and SprintHelm | In place |
| AES-256 encryption at rest for all stored data | In place |
| Jira OAuth tokens are separately encrypted with AES-256-GCM under a per-environment master key before they are written to the database | In place |
| Key custody moved to a managed KMS with automatic rotation | Not yet available |
Access control
Every record in the database is scoped to the account that owns it, enforced by the database itself.
| Row-level security on every application table, scoping each record to its owning account. Enforced in Postgres, not only in application code | In place |
| Audit tables are readable by their owner and writable only by the service role | In place |
| OAuth 2.0 sign-in (Google) and email/password, with short-lived session tokens rotated on sign-in | In place |
| Single sign-on (SSO / SAML 2.0) | Not yet available |
| Role-based access control within a shared account (admin / member) | Not yet available |
Data handling
Your backlog is your roadmap. We hold as little of it as possible, in the EU, and never train on it.
| All customer data is stored and processed in the EU | In place |
| On Free and Pro, backlog data is processed in memory and not persisted. It is cleared when your session ends | In place |
| We never use your backlog, tickets or simulation inputs to train any AI model | In place |
| Customer data deleted from production within 30 days of account deletion or written request | In place |
| Alternative data residency regions (US or other) | Not yet available |
Application security
Standard web hardening, applied by default rather than per-route.
| Content Security Policy with a per-request nonce in production | In place |
| Rate limiting on authenticated API routes | In place |
| Inbound payment webhooks verified by cryptographic signature before processing | In place |
| Independent penetration testing | Not yet available |
Payments
We never see your card details.
| All card data is handled by Stripe. SprintHelm never receives or stores card numbers | In place |
| PCI DSS compliance is carried by Stripe as the payment processor | In place |
Auditability
Billing and integration activity is recorded, with timestamps and outcomes.
| Every plan change, payment event and notification is written to an append-only billing audit log with actor, timestamp, before/after plan and result | In place |
| Jira connection and import activity is recorded per workspace connection | In place |
| Customer-facing audit log export and search | Not yet available |
Compliance
GDPR today. SOC 2 is not done, and we say so.
| GDPR-compliant processing for EU users, with a Data Processing Agreement available on request | In place |
| Published sub-processor list, with 30 days' notice of material changes | In place |
| 72-hour breach notification to affected controllers | In place |
| We complete customer security questionnaires on request | In place |
| SOC 2 Type II certification | Not yet available |
Sub-processors
Third parties processing customer data on our behalf. 30 days' notice of material changes.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication and file storage | EU (West Europe) |
| Vercel | Application hosting and edge network | Global CDN |
| Stripe | Payment processing and subscription billing | US / EU |
| Anthropic | AI summary and PRD extraction inference | United States |
| Resend | Transactional email delivery | United States |
| Atlassian | Jira backlog import, only when you connect a Jira site | Per your Atlassian site region |