✦ Security · Trust Center

SpikedAI Trust & Security

SpikedAI is committed to protecting your revenue data. We build on enterprise-grade infrastructure and follow conservative data security principles to ensure your information remains yours.

Infrastructure

Global, redundant, isolated.

SpikedAI is built on world-class, multi-region cloud infrastructure. Designed for high availability, logical isolation, and rapid scalability.

Google Cloud Platform (GCP)

Primary workloads hosted in US-Central1 (Iowa) on Cloud Run, with isolated VPC networking and GCP's global perimeter defense.

Supabase Pro

Database and auth layers managed by Supabase — enterprise-grade JWT auth and high-concurrency database clusters.

Automated Backups

Point-in-time recovery and daily database backups with 7-day retention across all production environments.

Quick Facts

  • Hosting LocationUS-Central1 (GCP)
  • Auth MethodJWT / Supabase Auth
  • Data RedundancyMulti-Zone
  • Encryption MethodAES-256 / TLS 1.2+
  • Uptime Targeting99.9%
Data Protection

Encryption & isolation by default.

Rigorous data protection controls ensure personal information and meeting data are encrypted and isolated.

Encryption

All customer data is encrypted in transit over public networks using TLS 1.2+ protocols. Data at rest is encrypted using provider-managed AES-256 keys on Google Cloud Storage and Supabase (PostgreSQL).

  • FIPS 140-2 compliant hardware
  • Perfect Forward Secrecy

Multi-Tenant Isolation

SpikedAI uses logical isolation to ensure your data is siloed. Every database record is scoped to your organization ID, with strict Row-Level Security (RLS) enforcement at the infrastructure layer.

  • No cross-tenant data leakage
  • Tenant-scoped Bearer JWTs
AI Privacy

Clear boundaries on AI.

We are committed to a transparent AI policy. SpikedAI leverages best-in-class generative models while maintaining strict boundaries on data usage.

"SpikedAI does NOT use customer data to train foundation models without explicit authorization."

Subprocessor Vetting

We partner with foundational providers including Stripe and Google. All AI subprocessors are vetted for security and privacy commitments.

Grounding & RAG

Source-grounded retrieval-augmented generation based strictly on your organization's context, so answers stay accurate and traceable to their sources.

Human-in-the-Loop

All AI-generated signals and transcripts are designed for human review and verification before being committed to your CRM.

Integrations

Least-privilege by design.

Integrations are opt-in, user-authorized, and request the narrowest scope that makes the feature work.

Google Calendar (Read-Only)

The Google Calendar integration is opt-in and authorized by the user through Google's OAuth consent screen. We request a single read-only scope — calendar.readonly — so SpikedAI can see upcoming meetings, attendees, and timing, and prepare account context before a call. SpikedAI never creates, edits, or deletes events.

  • Read-only scope, no write access
  • Revocable anytime from your Google Account

Google Limited Use

SpikedAI's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Calendar data is used only to provide user-facing features.

  • Never sold or used for advertising
  • Never used to train generalized AI models

Full detail on the calendar data we access and how long we keep it is in our Privacy Policy.

Contractual Safeguards

Data Processing Agreement

SpikedAI provides a standard DPA, including Standard Contractual Clauses (SCCs), to ensure your data is protected across jurisdictions.

  • GDPR Article 28 Compliance
  • Data Breach Notification
  • International Transfer Safeguards

Don't wing it,
Win it.