Skip to main content

TRUST CENTER

ISO 27001 certified, GDPR-compliant AI sales assistant — EU data residency, security, and trust

Security and trust at Spiich.

Spiich is an agentic sales platform for B2B sales teams, built for security and privacy from the ground up. Your data is encrypted, stored and processed in the EU, and never used to train AI models.

ISO 27001 certifiedGDPR compliantEU hostedNo model trainingEncrypted in transit and at rest

Last updated August 16, 2026

How we protect your data

Security controls span encryption, access, infrastructure, and the way our AI handles your data.

Encryption

  • TLS 1.2 or higher required on all public endpoints
  • AES-256 encryption at rest for databases and object storage
  • Encryption keys managed in a dedicated secrets manager
  • Passwords stored using a salted, industry-standard hashing algorithm; OAuth tokens encrypted at rest

AI & data use

  • Customer content is never used to train or fine-tune AI models
  • Zero data retention terms with all language-model providers
  • AI inference runs in EU regions
  • External content read by agents is treated as untrusted input, never as instructions

Access control

  • CRM access is bounded by OAuth scopes an admin approves, with object and field-level locking
  • Least-privilege access, with separate identities per service and no shared administrator account
  • MFA enforced on all core internal systems
  • Integrations can be disconnected in one click, which clears stored tokens

Infrastructure

  • Built on managed, automatically patched cloud infrastructure
  • Every customer's data is logically isolated from every other tenant's
  • Dual-region redundancy within the EU for storage and backups
  • Dependencies continuously monitored and scanned for vulnerabilities

Privacy & governance

  • GDPR-based Data Processing Agreement available on request
  • Data subject rights supported: access, erasure, and portability
  • EU-only data residency for customer production data
  • Defined retention with export and deletion available on request

Monitoring & resilience

  • Centralized logging and monitoring across our infrastructure, with alerting
  • Agent activity logged and monitored for anomalies
  • Automated database backups with point-in-time recovery
  • Incident response with breach notification within 48 hours (GDPR Art. 33)

Data residency

All customer production data is stored and processed within the EU. The only exception is agent web search, which sends tenant-unattributed queries to US providers with zero data retention.

Application & database

Hosted and processed within the EU

AI inference

Runs within the EU

Backups & redundancy

Dual-region redundancy within the EU

Documentation

These documents are available to customers and prospects on request. Reach out and we will share access promptly.

ISO 27001 certificate and Statement of Applicability

Our certificate and the controls it covers.

Request access ↗

Data Processing Agreement (DPA)

Our standard GDPR data processing terms.

Request access ↗

Sub-processor list

Current sub-processors and what each one processes.

Request access ↗

CASA Tier 2 assessment

Cloud application security assessment (TAC Security, Nov 2025).

Request access ↗

Architecture & data-flow overview

How data is stored, processed, and transferred.

Request access ↗

DORA addendum

For regulated financial institutions.

Request access ↗
Request all documents

Frequently asked questions

The questions we are asked most often in security reviews. Can't find what you need? Email hello@spiich.ai.

Data & privacy

All customer production data is stored and processed within the EU, with dual-region redundancy for resilience. The only exception is agent web search, which sends tenant-unattributed queries to US providers with zero data retention.
Yes. TLS 1.2 or higher is required on all public endpoints, and data is encrypted at rest with AES-256 across our database and object storage. Encryption keys are held in a dedicated secrets manager.
Yes. We operate under a GDPR-based Data Processing Agreement, store and process customer production data within the EU, and meet the Article 33 breach-notification obligation. Our privacy policy is public.
Customers can request deletion or export of recordings, transcripts, and associated data through support or the DPA process, and can disconnect any integration from the app at any time, which clears the related stored tokens.
Customer data is available for export for 30 days after termination. After that window it is deleted, except for copies in routine backups (purged on our standard backup retention cycle) and data we are legally required to retain.
No security incidents have occurred to date.
Customer production data stays in the EU: the application, database, AI inference, and backups all run in EU regions. The one exception is agent web search, which sends tenant-unattributed queries to US search providers under zero-data-retention terms. Sub-processors are engaged under a Data Processing Agreement and are predominantly EU-hosted; where one sits outside the EU, the transfer is covered by an adequacy decision or by the EU standard contractual clauses with a transfer impact assessment, as set out in our privacy policy. The current sub-processor list, naming each sub-processor and what it processes, is available on request.
Yes. You contract with Spiich Labs AB, a Swedish company, under Swedish law, and your production data is stored and processed within the EU, so the controller-to-processor relationship stays inside the EU and there are no standard contractual clauses for you to sign with us. Where a transfer does happen behind the service, such as the agent web search above, the safeguards are ours to carry: an adequacy decision, or standard contractual clauses with a transfer impact assessment, built into our agreements with those recipients rather than into anything you have to arrange. Our GDPR-based Data Processing Agreement covers the processing and is available on request.

Hosting & infrastructure

Spiich is hosted entirely within the EU on managed, enterprise-grade cloud infrastructure.
Spiich does use sub-processors. Each one is engaged under a Data Processing Agreement, predominantly EU-hosted, with zero-data-retention terms where applicable. Our complete, current sub-processor list, naming each sub-processor and what it processes, is available on request.
Every customer's data is logically isolated from every other customer's, enforced at the data layer and again on every application request. Services run under separate, least-privilege identities, so one tenant's data is never reachable from another's context.
Automated database backups with 15-day retention and point-in-time recovery, deletion protection on the production database, and dual-region redundancy within the EU for storage and backups.

AI model use and safeguards

No. None of our model providers train, fine-tune, or improve their models on Spiich prompt or inference data, and our public terms confirm customer content is not used to train AI models. Inference runs under zero-data-retention terms in EU regions.
We work only with established enterprise AI providers, and each one is named in our sub-processor list, available on request. Every provider contractually commits to zero data retention and to never training on customer data, with all inference running in EU regions.
All external content an agent reads, such as email, calendar invitations, and web pages, is treated as untrusted input and never as instructions. Agent actions are constrained to validated operations inside the CRM scopes an admin has approved, and write actions carry guardrails against bulk or unintended changes.

Security & compliance

Spiich is certified to ISO/IEC 27001:2022 under certificate 110826-1, issued in August 2026. We also hold a CASA Tier 2 certification (TAC Security, November 2025) and operate under a GDPR-based Data Processing Agreement.
Spiich is ISO 27001 certified. Our certification is to ISO/IEC 27001:2022 under certificate 110826-1, issued in August 2026 by an accredited third-party certification body. SOC 2 is on our compliance roadmap. Alongside ISO 27001 we hold a CASA Tier 2 certification (TAC Security, November 2025). The certificate and our Statement of Applicability are available on request.
The certified scope is the development, operation, delivery and support of Spiich’s agent-based AI sales assistant SaaS platform, including the supporting cloud production environment, product engineering, customer support, and the associated internal business operations. In other words it covers the product you use and the systems behind it, not a subset. The certification runs for three years and is maintained through annual surveillance audits.
Not yet. We support email and password plus OAuth for connected integrations. SSO via SAML and OIDC is in progress and not currently available.
We run automated OWASP-based application security scans against our backend and frontend as part of CASA Tier 2 (TAC Security), alongside the internal audit programme our ISO 27001 certification requires and ongoing internal security testing.
We support email and password, with passwords stored using a salted, industry-standard hashing algorithm, plus OAuth for connected integrations and short-lived access tokens that rotate frequently.
Incident response is owned by engineering leadership, with defined roles for detection, containment, and recovery. Customers are notified of a confirmed personal-data breach without undue delay, and at most 48 hours after detection, per GDPR Article 33.
Access follows least privilege: per-service IAM roles with no shared root account, MFA on core internal systems, and human access to production limited to a small number of senior engineers for policy-compliance purposes.