We employ enterprise-grade security and privacy controls. You might also be interested in reviewing our Terms of Service and our Privacy Policy.
Data is stored in AWS in US data centers. As such, Sprintful inherits the control environment which AWS maintains and demonstrates via SSAE16 SOC 1, 2 and 3, ISO 27001 and FedRAMP/FISMA reports and certifications.
We follow best practices in SaaS data security including SSL encryption, logging, and two-factor authentication.
We monitor our systems 24/7/365 with a variety of performance measurement and error-checking tools. When problems are detected, our ops team is notified immediately, and the issues are investigated.
We integrate with most services (e.g. Google Calendar, Zoom, etc) via OAuth. Authentication tokens are stored in an external service with hardware security module. Given that our data-at-rest is encrypted, and oauth data are encrypted too, therefore these access tokens are double encrypted and only accessible by authorized systems. We do not store any data from external services (such as Google Calendar or Zoom) other than the bare minimum metadata to identify those accounts.
We have redundancy designed around all major components of our infrastructure (servers, database) spread across multiple availability zones. Automated backups are created on daily basis.
If you discover a vulnerability, we would like to know about it so we can take steps to address it as quickly as possible.
Please do the following:
What we promise: