Product security
We design product security around access control, authentication, secure development, and review of security-relevant changes. Current practices and evidence are available for scoped review.
The Trust Center describes Spacetime's current security-program posture and evidence boundaries for enterprise reviewers.
Materials may be shared after we understand your review scope and any confidentiality or authorization requirements. Availability does not by itself establish certification, legal compliance, or suitability for a particular environment.
These topics correspond to the categories in our current Trust Center. Wording is limited to documented posture and evidence availability.
We design product security around access control, authentication, secure development, and review of security-relevant changes. Current practices and evidence are available for scoped review.
Security-related reports may be available for review, subject to report scope, confidentiality, authorization, and the report's own terms.
We maintain security and control questionnaires as applicable to the requesting review. A completed questionnaire is not a certification or independent audit opinion.
We use documented safeguards intended to protect data in the environments and workflows within our control. Applicable safeguards depend on service scope and customer configuration.
Our application-security program includes security review and monitoring activities appropriate to the application and its stage. Details are available for a scoped review.
We assess security and reliability considerations for AI use in our operations and products. Specific controls, model boundaries, and evidence depend on the use case.
We consider environmental, social, and governance factors in company operations and decision-making. Any formal reporting or assessment is identified by its scope and status.
Commercial and security matters are reviewed through appropriate internal and legal processes. Legal review does not constitute a warranty or a statement of regulatory compliance.
We use privacy practices appropriate to the information and services in scope. Privacy obligations and rights depend on applicable law, role, jurisdiction, contract, and processing context.
Access is managed according to documented authorization and review practices. Control operation, exceptions, and evidence depend on the system and period under review.
We select and operate infrastructure using security and resilience considerations appropriate to the service. Provider controls and shared responsibilities remain part of the review scope.
We apply endpoint safeguards appropriate to corporate devices and operating environments. Coverage and evidence vary by asset, platform, configuration, and deployment status.
We use network controls and monitoring intended to reduce exposure to unauthorized activity. No network control prevents every threat or replaces customer-side responsibilities.
We maintain internal security practices for company operations and review them as the organization evolves. Specific evidence is provided only for the agreed scope.
Security and privacy policies are maintained according to organizational needs and applicable review scope. Policy existence does not by itself prove effective operation.
We do not present third-party security ratings as certification or as a substitute for a customer review. Any published rating will identify its source, date, scope, and limitations.
We maintain an incident-response process for security events within our defined scope. Response timing, notification duties, and customer responsibilities are governed by applicable agreements and facts.
We identify and manage security risks through documented processes appropriate to the organization. Risk decisions are context-dependent and do not eliminate residual risk.
We maintain inventories and ownership practices for assets within the relevant corporate and service scope. Inventory completeness depends on system boundaries and source data.
We maintain continuity and recovery planning appropriate to our operating environment. Recovery objectives, testing evidence, and dependencies are scope-specific and are not guarantees of uninterrupted service.
We provide security-awareness and role-appropriate training as part of our internal security program. Training completion and content are evaluated within the applicable period and population.
Security-relevant changes are subject to documented review and approval practices appropriate to the system. Change controls do not imply that every change is risk-free.
Physical and environmental protections are addressed through our facilities and infrastructure responsibilities. Provider controls and shared-responsibility boundaries apply where relevant.
We monitor selected systems and signals for security-relevant activity and vulnerabilities. Monitoring scope, cadence, detection limits, and response depend on the environment and service.
Tell us your product, control, privacy, or procurement scope. We will identify the appropriate evidence path and limitations before sharing material.
Request security documentation →