Security & Responsible Disclosure
Last updated: 7/26/2026
1. Our Approach
SparqOS is built on managed cloud infrastructure with encryption in transit (TLS), encryption at rest, scoped database access via row-level security, least-privilege service roles, and short-lived authentication tokens. Payments are handled by Paddle as Merchant of Record; we do not store card numbers.
2. Reporting a Vulnerability
If you believe you have found a security vulnerability in SparqOS, please report it privately to customerservice@smobilewireless.com with the subject line "SparqOS Security Report." Include:
- A clear description of the issue and its impact.
- Steps to reproduce, including any required accounts or payloads.
- Any logs, screenshots, or proof-of-concept code.
- Your name or handle if you want public credit.
We aim to acknowledge reports within 5 business days and to provide a status update within 15 business days.
3. Safe Harbor
We will not pursue civil or criminal action, or send a takedown to your ISP, for good-faith security research that:
- Stays within the scope below.
- Avoids privacy violations, service disruption, and destruction of data.
- Gives us a reasonable opportunity to fix the issue before disclosure.
- Does not exploit the issue beyond the minimum necessary to demonstrate it.
4. In Scope
- sparqos.ai and www.sparqos.ai
- Authenticated SparqOS application surfaces
- Public API endpoints under /api/public/*
5. Out of Scope
- Denial-of-service, volumetric, or brute-force attacks.
- Social engineering of SparqOS staff, partners, or customers.
- Physical attacks against our offices or hardware.
- Findings from automated scanners without a working proof-of-concept.
- Reports about missing best-practice headers without a demonstrated impact.
- Issues in third-party services (Paddle, model providers, infrastructure providers) — report those to the vendor.
6. Account Hygiene
You are responsible for keeping your password strong and unique, enabling any multi-factor option offered, and notifying us promptly at customerservice@smobilewireless.com if you believe your account has been compromised.