Trust Center

Everything procurement asks for, before they have to ask.

Search our controls, pages and answers to finish your security questionnaire yourself. We mark what we have, what is in progress, and what we do not have yet.

Contact security Browse resources

Compliance

  • Authorized lab, 48 requirements, Google data path

  • Third-party penetration test Testing in October 2026

    An external firm. Public summary when done, full report on request

  • SOC 2 Type II Not held

    We do not imply otherwise. Readiness package on request

  • ISO 27001 Not held

    On the roadmap, no committed date

  • FedRAMP, PCI-DSS Not held

    Not pursued in Year 1

  • HIPAA Deployable, not certified

    BAA executable per customer

  • GDPR Deployable, not certified

    DPA with SCCs, crypto-shred erasure

Start here

Most reviewers need one of these.

For your IT and security team

One page to forward to whoever has to approve Bolt: vendor identity, exactly what leaves the endpoint, every permission and what happens if it is denied, storage and encryption, code signing, current assurance status including what we do not have, and managed deployment. Written for the reviewer rather than for the buyer.

Blocked by your Google Workspace admin

What Google's “Access blocked: your institution's admin needs to review Bolt by Sparcle” screen means, and the two ways past it: run Bolt on an OAuth client you own so it is first-party inside your own tenant, or allowlist Sparcle's client IDs in the Admin console. Publishes both client IDs, every scope Bolt requests and what each one cannot do, and a request block an administrator can decide on without a call.

Independent security assessment (Google CASA)

Bolt was assessed by an authorized third-party lab against the 48 requirements of Google's CASA programme, and Google granted restricted access to Gmail data on the strength of it. States plainly what the assessment covers, what it proves, and what it does not: it is not a penetration test and it is not SOC 2.

Prove it yourself: watch what Bolt sends

A read-only script, and the manual equivalents, that show every connection Bolt opens on your own machine and name each one against our published list. Includes a real sample run, what you should expect to see, and an honest account of what the method cannot tell you.

Verify your download

The release signing public key, and the exact commands to prove a Bolt download came from us and was not tampered with. Also states where platform trust stands: macOS builds are signed with an Apple Developer ID and notarized, Windows is signed with an EV certificate, and the page is explicit that SmartScreen can still warn.

Network allowlist for enterprise proxies

The exact hostnames to allow so Bolt can be downloaded, updated, and run behind a secure web gateway, with per-vendor steps for Palo Alto, Zscaler, Cisco Umbrella, Netskope, and Fortinet. Written to be forwarded to a network admin without edits.

All resources and documents on request

Latest updates

What changed recently.

  • 2026-11 · planned

    SOC 2 auditor decision

    Choosing an audit firm. We will name it and a time window here once signed. Details

  • 2026-10

    Third-party penetration test scheduled

    An external firm tests Bolt in October 2026. The summary will be published here. Details

  • 2026-09-30

    Release signing key rotated

    Precautionary; no compromise of the previous key is known. v0.1.165 is the first release signed by the new key. Details

All updates

Why this exists

Buyers should not have to wait on us.

Answers before you ask

Your security, legal and TPRM teams should find what they need before a call. Most of what is here used to need an NDA and a five-day wait.

Plain about what we do not have

Deployable is not certified. Planned items stay on the page. We do not hold SOC 2 today, and we do not show a badge we do not hold.

Sparcle does not host your data

Bolt and Aeira run inside your perimeter. In every shipping topology, customer data does not reach Sparcle. The subprocessor list reflects that.

Talk to us.

If your team has read what is here and wants to go further, book a security or architecture review. Most pilots start with a 30-minute call and a mutual NDA.