Back to Trust Center

SprintHelm — Security controls summary

Controls inventory

21 of 28 controls in place · 7 not yet available · Last reviewed 4 August 2026

Certification status: We are not SOC 2 certified.

No audit window is booked and no report exists. We would rather you learn that here than after you have signed. What we can do today: complete your security questionnaire, sign a DPA, and walk you through the controls inventory below, which lists exactly what is in place and what is not.

Encryption

Data is encrypted in transit and at rest, and integration credentials get a second layer.

TLS 1.3 for all traffic between your browser and SprintHelmIn place
AES-256 encryption at rest for all stored dataIn place
Jira OAuth tokens are separately encrypted with AES-256-GCM under a per-environment master key before they are written to the databaseIn place
Key custody moved to a managed KMS with automatic rotationNot yet available

Access control

Every record in the database is scoped to the account that owns it, enforced by the database itself.

Row-level security on every application table, scoping each record to its owning account. Enforced in Postgres, not only in application codeIn place
Audit tables are readable by their owner and writable only by the service roleIn place
OAuth 2.0 sign-in (Google) and email/password, with short-lived session tokens rotated on sign-inIn place
Single sign-on (SSO / SAML 2.0)Not yet available
Role-based access control within a shared account (admin / member)Not yet available

Data handling

Your backlog is your roadmap. We hold as little of it as possible, in the EU, and never train on it.

All customer data is stored and processed in the EUIn place
On Free and Pro, backlog data is processed in memory and not persisted. It is cleared when your session endsIn place
We never use your backlog, tickets or simulation inputs to train any AI modelIn place
Customer data deleted from production within 30 days of account deletion or written requestIn place
Alternative data residency regions (US or other)Not yet available

Application security

Standard web hardening, applied by default rather than per-route.

Content Security Policy with a per-request nonce in productionIn place
Rate limiting on authenticated API routesIn place
Inbound payment webhooks verified by cryptographic signature before processingIn place
Independent penetration testingNot yet available

Payments

We never see your card details.

All card data is handled by Stripe. SprintHelm never receives or stores card numbersIn place
PCI DSS compliance is carried by Stripe as the payment processorIn place

Auditability

Billing and integration activity is recorded, with timestamps and outcomes.

Every plan change, payment event and notification is written to an append-only billing audit log with actor, timestamp, before/after plan and resultIn place
Jira connection and import activity is recorded per workspace connectionIn place
Customer-facing audit log export and searchNot yet available

Compliance

GDPR today. SOC 2 is not done, and we say so.

GDPR-compliant processing for EU users, with a Data Processing Agreement available on requestIn place
Published sub-processor list, with 30 days' notice of material changesIn place
72-hour breach notification to affected controllersIn place
We complete customer security questionnaires on requestIn place
SOC 2 Type II certificationNot yet available

Sub-processors

Third parties processing customer data on our behalf. 30 days' notice of material changes.

ProviderPurposeLocation
SupabaseDatabase, authentication and file storageEU (West Europe)
VercelApplication hosting and edge networkGlobal CDN
StripePayment processing and subscription billingUS / EU
AnthropicAI summary and PRD extraction inferenceUnited States
ResendTransactional email deliveryUnited States
AtlassianJira backlog import, only when you connect a Jira sitePer your Atlassian site region

Security questionnaires and a Data Processing Agreement are available on request: enterprise@sprinthelm.com

sprinthelm.com/security/controls · Reviewed 4 August 2026 · This summary is generated from the live Trust Center, so it reflects the state of the product on the date above.