Enterprise-Grade Security for Every Yard
Your scrap data is mission-critical. ReSpark protects it with SOC 2 Type II certified infrastructure, AES-256 encryption, and multi-zone redundancy built on AWS.
Request a DemoBuilt to protect your business.
SOC 2 Type II Certified
Independently audited against the highest standards for security and availability.
AES-256 Encryption
All data is encrypted at rest and in transit using AES-256 and TLS 1.2+.
Role-Based Access Control
Permission employees with view, edit, or no-access controls on every feature.
Tenant-Isolated Data
Each organization gets dedicated logical and physical storage partitions. Your data is completely separate.
Multi-Factor Authentication
MFA adds an extra layer of security by requiring a second form of verification at login.
Single Sign-On (SSO)
Authenticate through your existing identity provider without requiring separate credentials.
Secure Password Protocol
ReSpark uses SRP (Secure Remote Password). We never have access to your password, and neither does our cloud provider.
Vulnerability Management
Continuous monitoring of production infrastructure and applications to identify and resolve potential threats.
Reliable cloud infrastructure you can count on.
ReSpark runs on AWS with multi-zone redundancy, automated failover, and continuous backups. Your operations stay online even when the unexpected happens.
High Availability
Our database infrastructure is deployed across three AWS availability zones with automatic failover. If an entire data center goes offline, your system stays up with zero manual intervention.
Automated Failover
Database failover completes in 30 to 120 seconds. Serverless compute continues operating in remaining zones with no downtime.
Continuous Backups
Streaming backups run continuously with point-in-time recovery capability. Nightly cluster snapshots provide an additional layer of protection.
Recovery Objectives
Critical platform services target a recovery time of under one hour and a recovery point of less than five minutes. File storage targets zero data loss through versioning and cross-region replication.
Secure File Storage
All files are stored in encrypted S3 buckets with strict access policies. Temporary file access uses pre-signed URLs that expire within 10 minutes to one hour and grant access to only one file at a time.
Automated Patching
Security patches and database engine updates are deployed automatically through AWS during off-hours maintenance windows. Rolling updates across redundant nodes ensure zero service disruption.
Real-Time Monitoring
Amazon CloudWatch tracks database performance, resource utilization, and connections around the clock. Custom alarms trigger immediate engineering response when thresholds are exceeded.
Trusted by the standards that matter.
SOC 2 Type II
ReSpark is SOC 2 Type II certified, independently validated against the AICPA Trust Service Criteria for Security and Availability. Attestation reports are available to customers upon request.
Annual Penetration Testing
Independent third-party security firms conduct annual penetration testing of our platform and infrastructure. Executive summaries are available under NDA.
AWS Compliance Inheritance
Our infrastructure runs on AWS Aurora, which undergoes regular compliance certifications including SOC, ISO, and PCI DSS.
Cyber Insurance
ReSpark maintains cyber liability insurance coverage appropriate for our operations. Certificates are available upon request.
Incident Response
A documented incident response plan defines severity tiers, response times, and escalation paths. Critical threats are addressed within 15 minutes. Affected customers are notified with clear details on impact and remediation.
Disaster Recovery Testing
Backup restoration is tested semi-annually. Full disaster recovery simulations are conducted annually. All procedures are version-controlled and updated after each test.
Frequently Asked Questions
ReSpark is built from the ground up for maximum data security on AWS. Your data is encrypted, continuously monitored, and stored redundantly across multiple availability zones so a copy survives any single-facility failure.
SOC 2 Type II is one of the most rigorous information security standards in the world. It validates that our security controls are not only designed properly but operating effectively over time. The certification requires ongoing annual renewal.
Never. Each customer's data is tenant-isolated at the application and database levels. No customer can access another customer's data under any circumstances.
Yes. Admins control view, edit, and no-access permissions on every feature. Additional controls are available for sensitive actions like entering prices and weights.
All data at rest is encrypted with AES-256. All data in transit is protected by TLS 1.2+. File assets are stored in encrypted S3 buckets with server-side encryption keys.
Our infrastructure runs across three AWS availability zones. If one goes offline, automatic failover promotes a standby instance in 30 to 120 seconds. No manual intervention required.
Yes. You can export your data at any time through built-in export functionality in standard formats including CSV and JSON.
All customer data is stored and processed within the United States on AWS infrastructure. Data does not leave the continental US unless specifically requested and documented.
Yes. ReSpark maintains a comprehensive disaster recovery plan with defined recovery time and recovery point objectives, tested semi-annually with full simulations conducted annually. Details are available upon request.
Security questions? Let's talk.
Our team can walk through our security practices, share our SOC 2 report, or discuss any compliance requirements you have.