Security

Spark Memory holds what your AI tools learn about your business, and it connects to your mail, chat, and documents. So you should know exactly how we look after it. This page says where your data is kept, who can see it, what we never keep, and how to reach us if something looks wrong.

Where your data is kept#

Your data lives on servers we run at DigitalOcean. Every connection to Spark Memory is encrypted, so nothing travels in the clear between your browser, your AI tools, and us.

Connection credentials, such as the tokens that let a memory read your Outlook inbox or your Google Drive folders, are stored encrypted with AES 256, and the key to unlock them is never stored next to them.

A backup is taken every night and kept for fourteen days. Backups follow the same access rules as the live data and a copy is kept apart from the server it came from.

Who can see what#

Your organization's data is kept apart from every other customer's. Each memory is its own store, and each room inside a memory is its own store too. Nothing reads across them except the audited gates you control.

These rules are checked again on every request. Nothing is trusted because an earlier step let it through.

Only a small number of named people at Solder Spark can reach the servers, and only over a private connection.

How people sign in#

Your team signs in with a Solder Spark account, or with their Microsoft work account if your organization uses enterprise single sign-on. Disabling an account ends its sessions straight away, and anyone can sign out of every device from their settings. Every sign-in, and every refused sign-in, is recorded in your organization's audit log.

What we never keep#

Some things should not exist in a memory at all. A bank account number, a card number, a government identifier, a password, an access key, a private key, or a one-time code is removed from every message before the memory reads it. The memory can know that a supplier changed banks without ever holding the account number. Names, email addresses, and phone numbers stay, because they are what a memory is for.

A message from outside your organization is treated as something somebody said, never as a fact you stated yourself, and nothing inside a message can promote itself to a higher level of trust.

How we use AI#

AI is used to read what comes in and to answer what you ask. Your data is never used to train any model, ours or anyone else's. Any AI provider we use is bound to keep nothing after the answer is produced and is barred by contract from training on your data.

Deleting your data#

You can remove a memory at any time, and you can ask us to delete your whole account. When you disconnect a source we delete our copy of its credential at once and, where the provider allows it, end our access on their side as well. Deleted data is gone from our backups within fourteen days.

How we test it#

We attack our own service on a schedule, using the same methods a real attacker would use, and we fix what we find before we write about it. We do not claim certifications we do not hold. The Compliance page lists each control we have in place and how it works, in the form a reviewer would ask for.

Reporting a problem#

If you think you have found a security issue, email contact@solderspark.com with what you found and how to reproduce it. A person will reply within two business days, and you will have a fix or a plan within ten.

We welcome good faith research. Test only against accounts and data you own, do not read or change other people's data, do not run denial of service tests, and give us reasonable time to fix a problem before you talk about it publicly. If you follow those rules we will not take legal action against you, and we will credit you if you want.

If something goes wrong#

If an incident ever affects your data, you hear it from us. We tell affected customers what happened, what was involved, what we did about it, and what you should do, as soon as we understand it and always within seventy-two hours of confirming it.

Our machine readable contact details are published at /.well-known/security.txt.