ReSpark Acquires ScrapRightLearn More →

Enterprise-Grade Security for Every Yard

Your scrap data is mission-critical. ReSpark protects it with SOC 2 Type II certified infrastructure, AES-256 encryption, and multi-zone redundancy built on AWS.

Request a Demo

Built to protect your business.

SOC 2 Type II Certified

Independently audited against the highest standards for security and availability.

AES-256 Encryption

All data is encrypted at rest and in transit using AES-256 and TLS 1.2+.

Role-Based Access Control

Permission employees with view, edit, or no-access controls on every feature.

Tenant-Isolated Data

Each organization gets dedicated logical and physical storage partitions. Your data is completely separate.

Multi-Factor Authentication

MFA adds an extra layer of security by requiring a second form of verification at login.

Single Sign-On (SSO)

Authenticate through your existing identity provider without requiring separate credentials.

Secure Password Protocol

ReSpark uses SRP (Secure Remote Password). We never have access to your password, and neither does our cloud provider.

Vulnerability Management

Continuous monitoring of production infrastructure and applications to identify and resolve potential threats.

Reliable cloud infrastructure you can count on.

ReSpark runs on AWS with multi-zone redundancy, automated failover, and continuous backups. Your operations stay online even when the unexpected happens.

3 Availability Zones
<5 min Recovery Point
30–120 sec Failover
AES-256 Encryption

High Availability

Our database infrastructure is deployed across three AWS availability zones with automatic failover. If an entire data center goes offline, your system stays up with zero manual intervention.

Automated Failover

Database failover completes in 30 to 120 seconds. Serverless compute continues operating in remaining zones with no downtime.

Continuous Backups

Streaming backups run continuously with point-in-time recovery capability. Nightly cluster snapshots provide an additional layer of protection.

Recovery Objectives

Critical platform services target a recovery time of under one hour and a recovery point of less than five minutes. File storage targets zero data loss through versioning and cross-region replication.

Secure File Storage

All files are stored in encrypted S3 buckets with strict access policies. Temporary file access uses pre-signed URLs that expire within 10 minutes to one hour and grant access to only one file at a time.

Automated Patching

Security patches and database engine updates are deployed automatically through AWS during off-hours maintenance windows. Rolling updates across redundant nodes ensure zero service disruption.

Real-Time Monitoring

Amazon CloudWatch tracks database performance, resource utilization, and connections around the clock. Custom alarms trigger immediate engineering response when thresholds are exceeded.

Trusted by the standards that matter.

SOC 2 Type II

ReSpark is SOC 2 Type II certified, independently validated against the AICPA Trust Service Criteria for Security and Availability. Attestation reports are available to customers upon request.

Annual Penetration Testing

Independent third-party security firms conduct annual penetration testing of our platform and infrastructure. Executive summaries are available under NDA.

AWS Compliance Inheritance

Our infrastructure runs on AWS Aurora, which undergoes regular compliance certifications including SOC, ISO, and PCI DSS.

Cyber Insurance

ReSpark maintains cyber liability insurance coverage appropriate for our operations. Certificates are available upon request.

Incident Response

A documented incident response plan defines severity tiers, response times, and escalation paths. Critical threats are addressed within 15 minutes. Affected customers are notified with clear details on impact and remediation.

Disaster Recovery Testing

Backup restoration is tested semi-annually. Full disaster recovery simulations are conducted annually. All procedures are version-controlled and updated after each test.

Frequently Asked Questions

ReSpark is built from the ground up for maximum data security on AWS. Your data is encrypted, continuously monitored, and stored redundantly across multiple availability zones so a copy survives any single-facility failure.

SOC 2 Type II is one of the most rigorous information security standards in the world. It validates that our security controls are not only designed properly but operating effectively over time. The certification requires ongoing annual renewal.

Never. Each customer's data is tenant-isolated at the application and database levels. No customer can access another customer's data under any circumstances.

Yes. Admins control view, edit, and no-access permissions on every feature. Additional controls are available for sensitive actions like entering prices and weights.

All data at rest is encrypted with AES-256. All data in transit is protected by TLS 1.2+. File assets are stored in encrypted S3 buckets with server-side encryption keys.

Our infrastructure runs across three AWS availability zones. If one goes offline, automatic failover promotes a standby instance in 30 to 120 seconds. No manual intervention required.

Yes. You can export your data at any time through built-in export functionality in standard formats including CSV and JSON.

All customer data is stored and processed within the United States on AWS infrastructure. Data does not leave the continental US unless specifically requested and documented.

Yes. ReSpark maintains a comprehensive disaster recovery plan with defined recovery time and recovery point objectives, tested semi-annually with full simulations conducted annually. Details are available upon request.

Security questions? Let's talk.

Our team can walk through our security practices, share our SOC 2 report, or discuss any compliance requirements you have.

The platform your operation will run on for the next 20 years.

Talk to the team. Understand where ReSpark creates real value for your operation.