Trust CenterStatus
Security and assurance

A clearer path through security review.

The Trust Center describes Spacetime's current security-program posture and evidence boundaries for enterprise reviewers.

Evidence boundary.

Materials may be shared after we understand your review scope and any confidentiality or authorization requirements. Availability does not by itself establish certification, legal compliance, or suitability for a particular environment.

Program areas

What reviewers can ask about.

These topics correspond to the categories in our current Trust Center. Wording is limited to documented posture and evidence availability.

Product security

We design product security around access control, authentication, secure development, and review of security-relevant changes. Current practices and evidence are available for scoped review.

Reports

Security-related reports may be available for review, subject to report scope, confidentiality, authorization, and the report's own terms.

Self-assessments

We maintain security and control questionnaires as applicable to the requesting review. A completed questionnaire is not a certification or independent audit opinion.

Data security

We use documented safeguards intended to protect data in the environments and workflows within our control. Applicable safeguards depend on service scope and customer configuration.

Application security

Our application-security program includes security review and monitoring activities appropriate to the application and its stage. Details are available for a scoped review.

AI

We assess security and reliability considerations for AI use in our operations and products. Specific controls, model boundaries, and evidence depend on the use case.

ESG

We consider environmental, social, and governance factors in company operations and decision-making. Any formal reporting or assessment is identified by its scope and status.

Legal

Commercial and security matters are reviewed through appropriate internal and legal processes. Legal review does not constitute a warranty or a statement of regulatory compliance.

Data privacy

We use privacy practices appropriate to the information and services in scope. Privacy obligations and rights depend on applicable law, role, jurisdiction, contract, and processing context.

Access control

Access is managed according to documented authorization and review practices. Control operation, exceptions, and evidence depend on the system and period under review.

Infrastructure

We select and operate infrastructure using security and resilience considerations appropriate to the service. Provider controls and shared responsibilities remain part of the review scope.

Endpoint security

We apply endpoint safeguards appropriate to corporate devices and operating environments. Coverage and evidence vary by asset, platform, configuration, and deployment status.

Network security

We use network controls and monitoring intended to reduce exposure to unauthorized activity. No network control prevents every threat or replaces customer-side responsibilities.

Corporate security

We maintain internal security practices for company operations and review them as the organization evolves. Specific evidence is provided only for the agreed scope.

Policies

Security and privacy policies are maintained according to organizational needs and applicable review scope. Policy existence does not by itself prove effective operation.

Security grades

We do not present third-party security ratings as certification or as a substitute for a customer review. Any published rating will identify its source, date, scope, and limitations.

Incident response

We maintain an incident-response process for security events within our defined scope. Response timing, notification duties, and customer responsibilities are governed by applicable agreements and facts.

Risk management

We identify and manage security risks through documented processes appropriate to the organization. Risk decisions are context-dependent and do not eliminate residual risk.

Asset management

We maintain inventories and ownership practices for assets within the relevant corporate and service scope. Inventory completeness depends on system boundaries and source data.

Business continuity and disaster recovery

We maintain continuity and recovery planning appropriate to our operating environment. Recovery objectives, testing evidence, and dependencies are scope-specific and are not guarantees of uninterrupted service.

Training

We provide security-awareness and role-appropriate training as part of our internal security program. Training completion and content are evaluated within the applicable period and population.

Change management

Security-relevant changes are subject to documented review and approval practices appropriate to the system. Change controls do not imply that every change is risk-free.

Physical and environmental

Physical and environmental protections are addressed through our facilities and infrastructure responsibilities. Provider controls and shared-responsibility boundaries apply where relevant.

Continuous monitoring

We monitor selected systems and signals for security-relevant activity and vulnerabilities. Monitoring scope, cadence, detection limits, and response depend on the environment and service.

Request evidence

Make the review specific.

Tell us your product, control, privacy, or procurement scope. We will identify the appropriate evidence path and limitations before sharing material.

Request security documentation