Security

Spare Data Security

Keeping our customers' data safe is our priority

At Spare, we are deeply committed to the security and privacy of your data. We continuously invest in robust security measures and independent audits to ensure your information is protected. For a detailed and real-time overview of our security posture, please visit our Trust Center.

Security & Compliance

We are proud to have our security practices and controls validated against globally recognized standards.

ISO 27001 Certified
Spare is ISO 27001 certified, demonstrating our adherence to the highest international standards for information security management.

SOC 2 Type II Compliant
We have successfully completed a SOC 2 Type II audit, validating the effectiveness of our security controls over time.

HIPAA Compliant
Spare meets the stringent requirements of the Health Insurance Portability and Accountability Act (HIPAA) to protect sensitive health information.

GDPR Compliant
We are committed to protecting the data rights of individuals in the European Union under the General Data Protection Regulation (GDPR).

Our Layered Approach to Security

We employ a defense-in-depth strategy to protect our systems and your data at every layer.

Your Central Hub for Security and Compliance

For complete transparency and to provide you with the most current information, we have centralized all of our security and compliance documentation in our Trust Center. This is your single source of truth for our security posture.

In the Trust Center, you can:

Payment Information

All payment processing is securely handled by Stripe, a certified PCI Level 1 Service Provider. We do not collect, store, or have access to any payment information on our servers.

Responsible Disclosure & Bug Bounty Program

We encourage everyone that practices responsible disclosure and complies with our policies to participate in our bug bounty program. Please avoid automated testing and only perform security testing with your own data. Do not disclose any information regarding vulnerabilities until we have had a chance to remediate them. Rewards are provided at our discretion depending on the criticality of the vulnerability reported.

You can report vulnerabilities by contacting security@spare.com. Please include a proof of concept. We will respond as quickly as possible to your submission and will not take legal action if you follow the rules.

Program Scope

In Scope:

Exclusions:

Accepted Vulnerabilities

Out of Scope Vulnerabilities

The following are out of scope for our bug bounty program:

Have Questions?

Your trust is important to us. If you have any general security-related questions, concerns, or feedback, please don't hesitate to reach out to our security team.

Contact us at: security@spare.com