Security
How SquadSpace protects your media, documents, and account — and where we are on the compliance journey.
In plain terms
We encrypt data in transit and at rest, run on established cloud infrastructure, limit access to production data, and disclose every vendor. We’re early — so we’re transparent about what’s in place today versus on the roadmap.
01How we protect your data
Encryption
Data is encrypted in transit with TLS. Media and documents are stored with our infrastructure providers using encryption at rest.
Infrastructure
The Service runs on established cloud providers (Supabase, Vercel, Mux, Cloudinary, Backblaze) with their own hardened security programs.
Access control
Access to production data is limited to what’s needed to operate the Service, protected by authentication and least-privilege principles.
Monitoring
We use error monitoring (Sentry) to detect and diagnose problems, and review logs for signs of abuse.
AI data handling
AI features send only the content needed for the task, to vetted providers that don’t train on your data by default.
Your Content
You own your content and control who you share it with. Share links use opaque tokens and are not indexed by search engines.
02Compliance status
We believe in showing where we actually are rather than displaying badges we haven’t earned.
03Subprocessors
We disclose every third-party vendor that processes data on the Subprocessors page, with a changelog of additions and removals.
04Report a vulnerability
Found a security issue?
We appreciate responsible disclosure and will work with you on any legitimate report.
§Contact
Questions about this document? Reach Ajay Shenoy at security@www.squadspace.co. Postal: Tokyo, Japan.