Skip to content
Centrasprit
Security

We take security seriously because that’s the product.

A platform that watches over your organization has to hold itself to the same standard. Here is how we approach it, conceptually — details are refined as our infrastructure matures.

Encryption

Data is encrypted in transit and at rest using industry-standard protocols.

Authentication

Strong authentication is required for access to administrative and organizational data.

Access control

Access to customer data is governed by role-based permissions tied to job function.

Least-privilege principles

Systems and personnel are granted only the access required to perform their function.

Data isolation

Each organization's data is logically separated from every other organization's data.

Auditability

Security-relevant actions are logged, so activity can be reviewed and investigated.

Secure integrations

Connections to third-party systems are scoped to the minimum access required.

Data retention

Data is retained only as long as necessary to provide the service, and is configurable per organization.

AI data boundaries

AI processing is scoped to security-relevant data and is not used to train models across customers.

Administrative controls

Organizations retain control over what Centrasprit can observe and what it is authorized to act on.

Centrasprit does not currently hold SOC 2, ISO 27001, HIPAA, GDPR, PCI DSS, or other third-party security certifications. We will update this page if and when any such certification is formally verified.