Security is a product feature. Here is how it works.
Sparring is built and operated by Carnegie Intelligent Technology Limited. This page describes our architecture, how customer data flows and is protected, what we log, how long we keep it, and how to reach us about a vulnerability. If you need something that isn't here, ask — [email protected].
Last updated 7 October 2026 · Questions: [email protected]
Architecture
Production runs on Google Cloud. Inference runs through a pluggable gateway chosen per tenant.
| Layer | What runs there | Notes |
|---|---|---|
| Edge | Cloudflare (DNS, TLS termination, WAF, bot management) | TLS 1.2+ enforced; HSTS |
| Application | Google Cloud Run — web (UI + API) and worker (debriefs, Arena runs, usage reporting) | Stateless containers; least-privilege service accounts |
| Data | Cloud SQL (PostgreSQL 16, private IP), Cloud Storage (exports) | Encrypted at rest (Google-managed keys); automated backups + PITR |
| Secrets | Secret Manager | No credentials in code, config files or database columns |
| Events | Pub/Sub (Marketplace entitlements), Service Control (usage) | Signed push subscriptions |
| Inference | Model gateway → standard channel (Anthropic wire) or Vertex AI (GCP-resident) per tenant | Model providers do not train on API traffic; see sub-processors |
Primary region
asia-east1 (Taiwan). EU (europe-west) and US (us-central) deployments on request for Platform customers.
Data residency option
Tenants may select GCP-resident inference (Vertex AI). Transcripts then never leave Google Cloud. Standard-channel tenants use the Anthropic API with zero data retention terms.
Data handling
What we collect, why, and what we do with it.
What is stored
Account identity (email, name, SSO subject), organisation settings, practice transcripts and debriefs, Arena transcripts and reports, Studio scenarios and uploaded source material, usage events, audit log.
Tenant isolation
Every row carries an organisation id; every query is scoped by it at the API layer. There is no cross-tenant read path. API keys are hashed; sessions are signed, HttpOnly, SameSite cookies.
Retention you control
Default 365 days for transcripts and debriefs, configurable per organisation. A nightly sweep deletes expired sessions. Usage and audit records are retained for billing and accountability. Learners can delete their own sessions at any time.
No training on your data
Your transcripts, scenarios and uploads are never used to train models — ours or any provider's — and never used to improve shared content.
Agent credentials (Arena)
Reference secrets by name; values live in Secret Manager and are read at run time. Transcripts of Arena runs are stored in your tenant like any other session.
Logging
Application logs contain identifiers and timings, not transcript content. The safety-protocol notification to your designated contact contains a session id and category — never the learner's words.
Application security
Controls that are live in production today.
- Google Workspace SSO (OIDC); domain auto-join; role-scoped invite links; no passwords stored
- Roles: owner, admin, manager, learner — enforced on every API route
- Per-user rate limiting; per-organisation monthly usage caps
- CSRF protection (origin checks on cookie-authenticated mutations)
- Input limits and schema validation (zod) on every write
- Audit log of administrative actions, exportable
- Dependencies scanned in CI; images rebuilt from pinned bases
- Secrets only in Secret Manager; rotated without redeploy of code
- Least-privilege service accounts per service (web, worker, migrate)
- Automated DB backups with point-in-time recovery
- Health probes and a watchdog with out-of-band alerting
- Infrastructure as code (Terraform) — reviewable, reproducible
When a conversation stops being practice.
If a learner discloses intent to harm themselves or others, or discloses abuse, the simulation stops before any model is called. Detection is deterministic (English and Chinese), so it cannot be argued out of. The learner sees crisis resources appropriate to the category; the session is locked; an audit event is recorded; and, if configured, your designated contact is notified with the session id and category only.
We tune this conservatively. It will occasionally pause a session on a figure of speech. For a product used by people under stress, we consider that the right trade.
What the data may never be used for.
- Practice scores and debriefs may not be used for hiring, firing, promotion or compensation decisions
- Covert evaluation of staff is prohibited; learners are told what managers can see, on every briefing
- Arena may only be run against agents you own or are authorised to test
- Scenarios may not be used to train people or agents to deceive, manipulate or harm
Compliance
Where we are, and where we are going. We would rather tell you than let a questionnaire surprise you.
| Item | Status | Detail |
|---|---|---|
| Data Processing Addendum (GDPR / UK GDPR / PDPO) | Available | Standard Contractual Clauses incorporated; sub-processor list published |
| Sub-processor list | Published | /legal/subprocessors |
| Hong Kong PDPO | Compliant | Data user: Carnegie Intelligent Technology Limited |
| Encryption in transit / at rest | In place | TLS 1.2+; Google-managed encryption at rest |
| Penetration test | Planned Q1 2027 | Third-party; summary available under NDA |
| SOC 2 Type I | Planned H1 2027 | Type II to follow after observation period |
| ISO 27001 | Evaluating | Dependent on customer demand |
| Vulnerability disclosure | Live | [email protected] |
Responsible disclosure
If you believe you have found a security vulnerability in Sparring, email [email protected] with steps to reproduce. We acknowledge within 2 business days, keep you informed, and credit you (if you wish) when the issue is fixed. Please do not access data that isn't yours, degrade the service, or disclose publicly before we have had a reasonable chance to remediate. We do not pursue legal action against good-faith research that follows these rules.
Incident notification
Confirmed incidents affecting your data are notified to your organisation owner within 72 hours of confirmation, with scope, impact and remediation — as required by our DPA.
Need a security questionnaire answered?
Send it. We answer in writing, usually within a week, and we'll tell you where we fall short rather than hedge.