Security Policy.
Last updated September 15th, 2026
Introduction
This policy describes the principal technical and organisational measures SparkLayer uses to protect its systems and customer data. It should be read alongside our Data Processing Agreement, Business Continuity Plan and Incident Management Policy.
Our security controls are reviewed as our systems, products and risks change.
Hosting and infrastructure
SparkLayer's production infrastructure is hosted on Google Cloud. Our production database runs in the europe-west2 (London) region, so customer data is held in the United Kingdom.
We rely on Google Cloud's physical and environmental security controls for the underlying data-centre infrastructure, while SparkLayer is responsible for the configuration and security of the systems and applications we operate on that infrastructure. Google's own controls are described at cloud.google.com/security.
Encryption
Customer data is encrypted in transit using TLS and encrypted at rest within Google Cloud. Encryption controls are configured and maintained as part of our production infrastructure.
Multi-factor authentication
Multi-factor authentication is required for access to production systems and is enabled across supported business systems. Staff are issued FIDO security keys for supported services, reducing reliance on one-time codes and SMS-based authentication.
Authentication controls are reviewed as part of our access-management process.
Access control
Access to production systems and customer data follows the principle of least privilege and is limited to personnel who require it for their role.
Access is reviewed periodically and revoked promptly when someone leaves SparkLayer or changes role. Production activity is logged and monitored.
Personnel security
Staff with access to SparkLayer systems are subject to confidentiality obligations and are required to follow our internal security policies.
These cover areas including account security, password management, device security, full-disk encryption, acceptable use, handling of customer data and incident reporting. Staff receive security and data-protection awareness guidance appropriate to their role.
Secure software development
Security is considered throughout our software development lifecycle. Our engineering practices include peer review, automated testing and controls around production deployment.
We use established security guidance, including relevant OWASP recommendations, when designing and reviewing application security controls.
Vulnerability and dependency management
We monitor and maintain the software and dependencies used in our production environment and prioritise remediation based on severity and risk.
Where practical, dependency and deployment processes are automated through our development and CI/CD tooling.
Backups and recovery
Systems containing customer data are backed up automatically every day. Backups are encrypted at rest, and point-in-time recovery is enabled for supported systems.
Backup and recovery arrangements form part of our business continuity processes and are tested periodically.
Review
We review this policy at least twice a year and when material changes are made to our systems or security controls. Relevant technical controls and response procedures are tested separately as part of our security, incident-management and business-continuity processes.