← Back

Security & Responsible Disclosure

Last updated: 7/26/2026

1. Our Approach

SparqOS is built on managed cloud infrastructure with encryption in transit (TLS), encryption at rest, scoped database access via row-level security, least-privilege service roles, and short-lived authentication tokens. Payments are handled by Paddle as Merchant of Record; we do not store card numbers.

2. Reporting a Vulnerability

If you believe you have found a security vulnerability in SparqOS, please report it privately to customerservice@smobilewireless.com with the subject line "SparqOS Security Report." Include:

  • A clear description of the issue and its impact.
  • Steps to reproduce, including any required accounts or payloads.
  • Any logs, screenshots, or proof-of-concept code.
  • Your name or handle if you want public credit.

We aim to acknowledge reports within 5 business days and to provide a status update within 15 business days.

3. Safe Harbor

We will not pursue civil or criminal action, or send a takedown to your ISP, for good-faith security research that:

  • Stays within the scope below.
  • Avoids privacy violations, service disruption, and destruction of data.
  • Gives us a reasonable opportunity to fix the issue before disclosure.
  • Does not exploit the issue beyond the minimum necessary to demonstrate it.

4. In Scope

  • sparqos.ai and www.sparqos.ai
  • Authenticated SparqOS application surfaces
  • Public API endpoints under /api/public/*

5. Out of Scope

  • Denial-of-service, volumetric, or brute-force attacks.
  • Social engineering of SparqOS staff, partners, or customers.
  • Physical attacks against our offices or hardware.
  • Findings from automated scanners without a working proof-of-concept.
  • Reports about missing best-practice headers without a demonstrated impact.
  • Issues in third-party services (Paddle, model providers, infrastructure providers) — report those to the vendor.

6. Account Hygiene

You are responsible for keeping your password strong and unique, enabling any multi-factor option offered, and notifying us promptly at customerservice@smobilewireless.com if you believe your account has been compromised.