Controls

Every control, with the page that proves it.

A tick means in place today. Caveats sit next to the tick. This is our self-assessment, not an auditor's attestation. We do not hold a SOC 2 report today.

Independent assurance

  • Independent assessment of the Google data path (Google CASA)

    TAC Security checked 48 requirements. Not a pentest, not SOC 2.

    In place ASSURE-01 Evidence SOC2 CC4.1 Verified 2026-10-08

  • Third-party penetration test

    Booked with an external firm, testing in October 2026. Summary published when done.

    In progress ASSURE-02 Evidence SOC2 CC4.1 Verified 2026-10-08

  • SOC 2 Type II report

    Not held today. We do not imply otherwise.

    Planned ASSURE-03 Evidence SOC2 Verified 2026-10-08

  • ISO 27001 certification

    On the roadmap, no committed date.

    Planned ASSURE-04 Evidence ISO 27001 Verified 2026-10-08

  • Annual penetration test cadence

    Follows the first test. On the internal security roadmap.

    Planned ASSURE-05 Evidence SOC2 CC4.1 Verified 2026-10-08

Release integrity

  • macOS builds signed with Apple Developer ID and notarized

    Issued to Sparcle Inc., ticket stapled. Verify with spctl.

    In place REL-01 Evidence SOC2 CC6.8 Verified 2026-10-08

  • Windows installer signed with an EV certificate

    SSL.com EV, key in a cloud HSM. SmartScreen can still warn.

    In place REL-02 Evidence SOC2 CC6.8 Verified 2026-10-08

  • Signed SHA-256 manifest for every release

    Minisign signature over all artifacts. Key rotated 2026-09-30, previous key still published.

    In place REL-03 Evidence SOC2 CC6.8 Verified 2026-10-08

  • CycloneDX SBOM per release

    Commit-pinned, published with the release.

    In place REL-04 Evidence SOC2 CC7.1 Verified 2026-10-08

  • Independent malware scan lookup per release

    Keyed to each file's hash.

    In place REL-05 Evidence SOC2 CC7.1 Verified 2026-10-08

  • Signed auto-updates

    Ed25519 key compiled into the client; unverified bundles refused.

    In place REL-06 Evidence SOC2 CC6.8 Verified 2026-10-08

  • Server images signed (cosign keyless)

    Fulcio and Rekor transparency log; admission policy examples.

    In place REL-07 Evidence SOC2 CC6.8 Verified 2026-10-08

  • SLSA build provenance

    Not claimed. Builds run on our own machines, which cannot attest to themselves.

    Planned REL-08 Evidence SLSA Verified 2026-10-08

Change management

  • Secret scan on every commit

    Sub-second scan of the staged diff.

    In place CHG-01 Evidence SOC2 CC8.1 Verified 2026-10-08

  • Advisory and licence scan at release

    Rust and npm advisories, licences, against a frozen build point. Pass, fail or unknown.

    In place CHG-02 Evidence SOC2 CC7.1 Verified 2026-10-08

  • Server image gate on CRITICAL and HIGH findings

    Trivy blocks the push; signing runs only after it passes.

    In place CHG-03 Evidence SOC2 CC7.1 Verified 2026-10-08

  • Independent pre-merge review of sensitive changes

    Being introduced for auth, crypto, licensing, audit chain and egress. Today automated gates approve.

    In progress CHG-04 Evidence SOC2 CC8.1 Verified 2026-10-08

  • Claims checked in the build

    A guard fails the build if a claim we cannot defend reappears.

    In place CHG-05 Evidence SOC2 CC2.3 Verified 2026-10-08

Data protection

  • AES-256-GCM envelope encryption with per-tenant keys

    Pluggable KMS. Local backend production-tested.

    In place DATA-01 Evidence HIPAA 164.312(a)(1), ISO A.10 Verified 2026-10-08

  • Desktop data encrypted at rest (SQLCipher)

    Caveat: a recovery copy of the device key sits on disk. Enforce FileVault or BitLocker.

    In place DATA-02 Evidence ISO A.10 Verified 2026-10-08

  • TLS for all data in transit

    Ingress with HSTS, Postgres, Redis, LLM calls. mTLS optional.

    In place DATA-03 Evidence SOC2 CC6.7, HIPAA 164.312(e) Verified 2026-10-08

  • Cryptographic erasure on request

    Per-tenant key destruction with a sealed receipt.

    In place DATA-04 Evidence GDPR Art. 17 Verified 2026-10-08

  • PII masked before any model call

    Always-on regex floor; free-text names need the model engine on.

    In place DATA-05 Evidence GDPR Art. 25 Verified 2026-10-08

  • AWS KMS and Vault Transit backends

    Reference implementations in integration testing.

    In progress DATA-06 Evidence ISO A.10 Verified 2026-10-08

  • Named-entity PII model on every platform

    Bundled on Apple Silicon; a separate scanner elsewhere. Off until an admin turns it on.

    In progress DATA-07 Evidence GDPR Art. 25 Verified 2026-10-08

  • FIPS 140-3 validated crypto module

    Algorithms are FIPS-eligible; validation pending.

    Planned DATA-08 Evidence FIPS Verified 2026-10-08

Identity and access

  • SSO with OIDC or SAML

    Okta, Entra ID, Google Workspace, Auth0, Zoho, any OIDC.

    In place IAM-01 Evidence SOC2 CC6.1, HIPAA 164.312(d) Verified 2026-10-08

  • SCIM 2.0 provisioning and deprovisioning

    Standard /scim/v2 mount; per-org tokens issued and revoked by admins.

    In place IAM-02 Evidence SOC2 CC6.2, SOC2 CC6.3 Verified 2026-10-08

  • MFA enforced at your identity provider

    Bolt accepts the IdP's assertion. We recommend MFA for every admin.

    In place IAM-03 Evidence SOC2 CC6.1 Verified 2026-10-08

  • Role-based access at several layers

    Session, admin-only, scope checks, per-tenant ACL with no admin bypass.

    In place IAM-04 Evidence SOC2 CC6.1, ISO A.9 Verified 2026-10-08

  • Privileged actions refuse when unaudited

    PII reveal and crypto-shred refuse if auditing is off.

    In place IAM-05 Evidence SOC2 CC6.1 Verified 2026-10-08

Audit and logging

  • Tamper-evident audit chain

    Merkle-sealed, Ed25519-signed.

    In place AUD-01 Evidence SOC2 CC7.3, HIPAA 164.312(b) Verified 2026-10-08

  • Standalone offline verifier

    One binary, no database, no KMS, no network. Sample bundle pre-NDA.

    In place AUD-02 Evidence HIPAA 164.312(c) Verified 2026-10-08

  • Serving region sealed into the audit chain

    Editing it breaks the signature.

    In place AUD-03 Evidence GDPR Art. 30 Verified 2026-10-08

  • SIEM forwarder (Splunk, Sentinel, syslog)

    Off by default. Best-effort, no retry buffer.

    In place AUD-04 Evidence SOC2 CC7.2 Verified 2026-10-08

  • Audit-seal operation itself sealed

    Still writes a log line, not a sealed record.

    In progress AUD-05 Evidence SOC2 CC7.3 Verified 2026-10-08

Endpoint and network

  • No telemetry; every outbound host published

    Only an update check leaves on its own.

    In place END-01 Evidence SOC2 CC6.6 Verified 2026-10-08

  • Watch what Bolt sends, on your own machine

    Read-only script names each connection against the list.

    In place END-02 Evidence SOC2 CC2.3 Verified 2026-10-08

  • Every local port and process disclosed

    Loopback only, mapped to MITRE ATT&CK.

    In place END-03 Evidence SOC2 CC2.3 Verified 2026-10-08

  • Managed deployment with MDM and Group Policy

    Force-install extension; settings pinned.

    In place END-04 Evidence SOC2 CC5.1 Verified 2026-10-08

  • Default-deny network policy for self-hosted

    Shipped in the Helm chart. Source-IP limits and mTLS are yours to add.

    In progress END-05 Evidence SOC2 CC6.6 Verified 2026-10-08

AI agent safety

  • Agent authority is named, never inferred

    Four controls between hostile content and an action.

    In place AI-01 Evidence OWASP LLM Verified 2026-10-08

  • Unknown is never reported as clean

    Four places the product says unknown.

    In place AI-02 Evidence SOC2 CC7.1 Verified 2026-10-08

  • Model runs where you choose

    On-prem, in-tenant cloud or public API. Minimum privacy tier enforceable.

    In place AI-03 Evidence GDPR Art. 28 Verified 2026-10-08

Vulnerability and incident response

  • Vulnerability disclosure policy with safe harbor

    1 business day to acknowledge; security.txt published.

    In place VIR-01 Evidence ISO A.16 Verified 2026-10-08

  • Patch targets: critical 7, high 30, medium 90 days

    Signed patch releases.

    In place VIR-02 Evidence SOC2 CC7.1 Verified 2026-10-08

  • Documented incident response, SEV1 to SEV4

    Five phases, acknowledgement and patch targets.

    In place VIR-03 Evidence SOC2 CC7.4, HIPAA 164.308(a)(6) Verified 2026-10-08

  • Breach notification clauses

    HIPAA 60-day and GDPR 72-hour for vendor-side incidents.

    In place VIR-04 Evidence GDPR Art. 33 Verified 2026-10-08

Privacy and subprocessors

  • Sub-processor disclosure with 30-day notice

    Separates customer sub-processors from Sparcle's own.

    In place PRIV-01 Evidence GDPR Art. 28, SOC2 CC9.2 Verified 2026-10-08

  • Customer data never hosted by Sparcle

    Every shipping topology keeps data in your perimeter.

    In place PRIV-02 Evidence GDPR Art. 28 Verified 2026-10-08

Company

  • Verified legal entity

    Delaware C-corp, verified by Apple and SSL.com.

    In place CO-01 Evidence SOC2 CC1.2 Verified 2026-10-08

  • Confidentiality and IP agreements for all personnel

    Condition of engagement.

    In place CO-02 Evidence ISO A.7 Verified 2026-10-08

  • Background checks

    Policy and vendor not yet adopted.

    Planned CO-03 Evidence SOC2 CC1.4 Verified 2026-10-08

  • Annual security awareness training

    Not yet running.

    Planned CO-04 Evidence SOC2 CC2.2, HIPAA 164.308(a)(5) Verified 2026-10-08

  • Security policy pack

    Policies for change, fraud risk and secure SDLC on the internal roadmap.

    Planned CO-05 Evidence SOC2 CC1.5, SOC2 CC5.3 Verified 2026-10-08

  • Independent board oversight

    No independent board seated yet.

    Planned CO-06 Evidence SOC2 CC1.2 Verified 2026-10-08

Map to a framework

How our controls map to the frameworks your auditor uses.

Each row names a control, the evidence behind it, and its status: In place, In progress or Planned.

SOC 2 Trust Services Criteria

We do not hold a SOC 2 report today. The rows below are our self-assessment, not an auditor's attestation.

CC1. Control environment

CC1. Control environment
ControlEvidenceStatus
CC1.1 Demonstrates commitment to integrity and ethical valuesSparcle Proprietary License; founder code-of-conduct (internal)In place
CC1.2 Board oversightSparcle Inc. is incorporated in Delaware; no independent board seated yetPlanned
CC1.3 Organizational structureSame as CC1.2Planned
CC1.4 Personnel competenceBackground-check policy on the internal security roadmapPlanned
CC1.5 Accountability for internal controlsPolicy pack rollout on the internal security roadmapPlanned

CC2. Communication and information

CC2. Communication and information
ControlEvidenceStatus
CC2.1 Quality information for internal controlOperations runbook, PII architecture doc, disaster-recovery doc, SIEM export guide (shared under NDA)In place
CC2.2 Internal communication of objectives and responsibilitiesAnnual security awareness training on the internal security roadmapPlanned
CC2.3 External communicationThis evidence map; Sub-Processor Disclosure; published compliance READMEIn place

CC3. Risk assessment

CC3. Risk assessment
ControlEvidenceStatus
CC3.1 Specifies suitable objectivesInternal production-readiness audit (available under NDA)In place
CC3.2 Identifies and analyzes riskInternal risk register (available under NDA); 30+ classified S1-S4 risksIn place
CC3.3 Considers potential for fraudPolicy pack on the internal security roadmapPlanned
CC3.4 Identifies and assesses changesChange-management policy on the internal security roadmapPlanned

CC4. Monitoring activities

CC4. Monitoring activities
ControlEvidenceStatus
CC4.1 Ongoing and separate evaluationsPrometheus and curated alerts in the Helm chart; a third-party penetration test is booked and not yet performed, and annual cadence thereafter is on the internal security roadmapIn progress
CC4.2 Internal communication of deficienciesIncident response framework published at /trust/incident-response: five phases, named intake at [email protected] via /.well-known/security.txt, acknowledgement and patch targets stated per severityIn place

CC5. Control activities

CC5. Control activities
ControlEvidenceStatus
CC5.1 Selects and develops control activitiesHelm chart with hardened defaultsIn place
CC5.2 Selects and develops technology controlsOperations runbook, Production Hardening Checklist (shared under NDA)In place
CC5.3 Deploys through policies and proceduresPolicy pack rollout on the internal security roadmapPlanned

CC6. Logical and physical access

CC6. Logical and physical access
ControlEvidenceStatus
CC6.1 Logical access securitySession middleware, admin-only middleware, per-handler OAuth scope checks, identity module, authorization module. Source-IP restriction and mTLS on admin endpoints are ingress-layer controls you configure; the chart does not ship them.In place
CC6.2 Authorization and authentication of usersAuthorization enforcement module, CSRF middleware (enforcing by default), SCIM 2.0 server at the standard /scim/v2/* mount point: full Users CRUD, with group membership set through the Users PATCH surface rather than a separate /Groups endpointIn place
CC6.3 Modification or removal of accessSCIM token issue / list / revoke via an authenticated admin endpointIn place
CC6.4 Restricts physical accessNot applicable. Sparcle does not operate physical infrastructure; customer-owned cloud.In place
CC6.5 Discontinues accessPer-person GDPR erasure (revokes OAuth grants, deletes sessions and credentials); per-org KMS crypto-shred via an authenticated admin endpointIn place
CC6.6 Restricts external accessHelm chart NetworkPolicy template, default-deny with explicit allow, enabled in the production values file. Source-IP restriction and mTLS are yours to add at the ingress; we do not ship them and do not claim them.In progress
CC6.7 Transmission of dataTLS at ingress (cert-manager); HSTS and security headers; session cookies Secure and SameSiteIn place
CC6.8 Prevention and detection of unauthorized softwareCosign keyless signing and admission policies (Sigstore Policy Controller, Kyverno examples)In place

CC7. System operations

CC7. System operations
ControlEvidenceStatus
CC7.1 Detection of vulnerabilitiesServer (container) path: the Trivy gate blocks CRITICAL and HIGH against the pushed image digest with a non-zero exit, and cosign keyless signing runs only after it passes. The SBOM attached in that pipeline is the builder's SPDX attestation; the CycloneDX SBOM is produced by a separate step, not by that workflow. Desktop path: a two-tier gate runs a secret scan on every commit and a full secrets, advisory and licence scan at release against a frozen build point.In progress
CC7.2 Monitoring of system performancePrometheus metrics; 8 alert groups plus audit hardening alerts in the chartIn place
CC7.3 Evaluation of security eventsMerkle-sealed audit chain covering authorization decisions, retrieval access, tool invocations, model calls, agent decisions, admin policy changes, the security-relevant identity transitions (sign-in, sign-out, session delegation and revocation, session attach) and the privileged key and identity operations (KMS rotation and crypto-shred, PII reveal, SCIM token issue and revoke). It does NOT yet cover the audit-seal operation itself, which still emits a log line rather than a sealed record; OAuth token refresh and the read-only SCIM token list are excluded on purpose and pinned by tests. SIEM forwarder with Splunk, Sentinel and syslog backends, off by default.In progress
CC7.4 Incident responseOperations runbook, Incident Workflow (shared under NDA; summarized publicly on /trust/incident-response)In place
CC7.5 Recovery from incidentsDisaster-recovery documentation (shared under NDA)In place

CC8. Change management

CC8. Change management
ControlEvidenceStatus
CC8.1 Authorizes, designs, develops, configures changesDevelop and configure: CI workflow (push and PR triggers), deploy workflow with Trivy gate, signed release artifacts. Authorize: independent pre-merge review is being introduced for changes to authentication, cryptography, licensing, the audit chain, and egress paths; today automated gates approve the merge. Until that review control is operating, we do not claim this criterion in full.In progress

CC9. Risk mitigation

CC9. Risk mitigation
ControlEvidenceStatus
CC9.1 Identifies, selects, develops risk mitigationBackup CronJob in chart with fail-closed S3 destination guardIn place
CC9.2 Assesses and manages risks of business partnersSub-Processor DisclosureIn place

HIPAA Security Rule

Sparcle ships HIPAA-deployable software that customers run in their own infrastructure. Deployable, not certified. A Business Associate Agreement is executable per customer. Controls on the customer side stay with the customer, per the deployment topology.

StandardImplementation specificationEvidenceStatus
164.308(a)(1)(i) Security Management ProcessRequired risk analysisInternal risk registerIn place
164.308(a)(3) Workforce SecurityAuthorization / supervision / terminationPending on the internal security roadmapPlanned
164.308(a)(5) Security Awareness and TrainingRequiredPending on the internal security roadmapPlanned
164.308(a)(6) Security Incident ProceduresRequired responseOperations runbook, Incident WorkflowIn place
164.308(a)(7) Contingency PlanRequired backup and DRDisaster-recovery documentation; backup CronJobIn place
164.312(a)(1) Access ControlUnique user id, automatic logoff, encryptionSession middleware; per-tenant CMK envelope encryption of stored secrets; conversation content sealed at restIn place
164.312(b) Audit ControlsRequiredMerkle-sealed audit chainIn place
164.312(c) IntegrityRequiredAudit-chain Merkle root and Ed25519 signingIn place
164.312(d) Person or Entity AuthenticationRequiredOIDC, SAML, SCIM via identity moduleIn place
164.312(e) Transmission SecurityRequired encryptionTLS ingress and DB TLS (SSL_MODE=require)In place
164.314(a) Business Associate ContractsRequiredCustomer BAA template; Anthropic BAA in progressPlanned

GDPR, article by article

ArticleRequirementEvidenceStatus
Art. 5(1)(f) Integrity and confidentialityAppropriate securityAggregate of CC6 and CC7 aboveIn place
Art. 17 Right to erasureErasure on requestPer-person erasure (self-service or admin DSAR) with a receipt; sealed audit records are retained. Per-org crypto-shred via an authenticated admin endpoint; tenant-scoped KMS shred at the trait layer (LocalKms production-tested; AwsKms, VaultKms reference impls in integration testing)In place
Art. 25 Data protection by designPseudonymization and encryption by defaultPII pseudonymization at LLM boundary and at tool-result to history boundary; per-tenant CMK envelope encryption of stored secrets; conversation content sealed at restIn place
Art. 28 Processor obligationsSub-processor disclosure and DPASub-Processor DisclosureIn place
Art. 30 Records of processing activitiesRequired loggingAudit chain and customer-side SIEM forwarderIn place
Art. 32 Security of processingPseudonymization, encryption, resilience, testingAggregate of aboveIn place
Art. 33 Notification of personal-data breach72-hour notificationIncident response framework published at /trust/incident-response, with contractual notification in the executed DPA. Sparcle holds no customer personal data, so the controller notification duty sits with the customer; we supply what they need to meet itIn place
Art. 35 DPIARequired for high-risk processingCustomer-driven (Sparcle is the processor; controller does the DPIA)Planned

ISO 27001, selected Annex A controls

We do not hold ISO 27001 certification. These rows are alignment evidence. Certification is a separate engagement.

Annex AControlEvidenceStatus
A.5 Information security policiesPolicies in placePending on the internal security roadmapPlanned
A.8 Asset managementAsset registerInternal asset registerPlanned
A.9 Access controlAuthorisation, removalSame as CC6In place
A.10 CryptographyKey managementPluggable KMS via aeira-traits Kms trait (Local production-tested; AWS, Vault reference impls in integration testing); cosign signing for releasesIn place
A.12 Operations securityLogging, monitoring, vulnerability managementSame as CC7In place
A.13 Communications securityNetwork securityHelm NetworkPolicy; TLSIn place
A.14 System acquisition, development, maintenanceSecure developmentSecure SDLC policy pending on the internal security roadmapPlanned
A.16 Information security incident managementIncident responseOperations runbook, Incident WorkflowIn place
A.17 Business continuityPlan and testsDisaster-recovery documentationIn place
A.18 ComplianceRegulatory complianceThis mapIn place

Status key

What the labels mean.

  • In place. Implemented, and evidence exists in the codebase, runbook or shipped artifacts.
  • In progress. Partly implemented. The gap is named in the row.
  • Planned. Not yet implemented. It stays on this page until it is.

This map is refreshed by hand when the thing it describes changes. If you find a row that has gone stale, tell us and we will treat it as a finding.

Need to map a control we have not listed?

Email us and we will add it for the next reviewer.