Sparring
Trust center

Security is a product feature. Here is how it works.

Sparring is built and operated by Carnegie Intelligent Technology Limited. This page describes our architecture, how customer data flows and is protected, what we log, how long we keep it, and how to reach us about a vulnerability. If you need something that isn't here, ask — [email protected].

Last updated 7 October 2026 · Questions: [email protected]

Architecture

Production runs on Google Cloud. Inference runs through a pluggable gateway chosen per tenant.

LayerWhat runs thereNotes
EdgeCloudflare (DNS, TLS termination, WAF, bot management)TLS 1.2+ enforced; HSTS
ApplicationGoogle Cloud Run — web (UI + API) and worker (debriefs, Arena runs, usage reporting)Stateless containers; least-privilege service accounts
DataCloud SQL (PostgreSQL 16, private IP), Cloud Storage (exports)Encrypted at rest (Google-managed keys); automated backups + PITR
SecretsSecret ManagerNo credentials in code, config files or database columns
EventsPub/Sub (Marketplace entitlements), Service Control (usage)Signed push subscriptions
InferenceModel gateway → standard channel (Anthropic wire) or Vertex AI (GCP-resident) per tenantModel providers do not train on API traffic; see sub-processors

Primary region

asia-east1 (Taiwan). EU (europe-west) and US (us-central) deployments on request for Platform customers.

Data residency option

Tenants may select GCP-resident inference (Vertex AI). Transcripts then never leave Google Cloud. Standard-channel tenants use the Anthropic API with zero data retention terms.

Data handling

What we collect, why, and what we do with it.

What is stored

Account identity (email, name, SSO subject), organisation settings, practice transcripts and debriefs, Arena transcripts and reports, Studio scenarios and uploaded source material, usage events, audit log.

Tenant isolation

Every row carries an organisation id; every query is scoped by it at the API layer. There is no cross-tenant read path. API keys are hashed; sessions are signed, HttpOnly, SameSite cookies.

Retention you control

Default 365 days for transcripts and debriefs, configurable per organisation. A nightly sweep deletes expired sessions. Usage and audit records are retained for billing and accountability. Learners can delete their own sessions at any time.

No training on your data

Your transcripts, scenarios and uploads are never used to train models — ours or any provider's — and never used to improve shared content.

Agent credentials (Arena)

Reference secrets by name; values live in Secret Manager and are read at run time. Transcripts of Arena runs are stored in your tenant like any other session.

Logging

Application logs contain identifiers and timings, not transcript content. The safety-protocol notification to your designated contact contains a session id and category — never the learner's words.

Application security

Controls that are live in production today.

  • Google Workspace SSO (OIDC); domain auto-join; role-scoped invite links; no passwords stored
  • Roles: owner, admin, manager, learner — enforced on every API route
  • Per-user rate limiting; per-organisation monthly usage caps
  • CSRF protection (origin checks on cookie-authenticated mutations)
  • Input limits and schema validation (zod) on every write
  • Audit log of administrative actions, exportable
  • Dependencies scanned in CI; images rebuilt from pinned bases
  • Secrets only in Secret Manager; rotated without redeploy of code
  • Least-privilege service accounts per service (web, worker, migrate)
  • Automated DB backups with point-in-time recovery
  • Health probes and a watchdog with out-of-band alerting
  • Infrastructure as code (Terraform) — reviewable, reproducible
Safety protocol

When a conversation stops being practice.

If a learner discloses intent to harm themselves or others, or discloses abuse, the simulation stops before any model is called. Detection is deterministic (English and Chinese), so it cannot be argued out of. The learner sees crisis resources appropriate to the category; the session is locked; an audit event is recorded; and, if configured, your designated contact is notified with the session id and category only.

We tune this conservatively. It will occasionally pause a session on a figure of speech. For a product used by people under stress, we consider that the right trade.

Ethical use

What the data may never be used for.

  • Practice scores and debriefs may not be used for hiring, firing, promotion or compensation decisions
  • Covert evaluation of staff is prohibited; learners are told what managers can see, on every briefing
  • Arena may only be run against agents you own or are authorised to test
  • Scenarios may not be used to train people or agents to deceive, manipulate or harm
Acceptable Use Policy

Compliance

Where we are, and where we are going. We would rather tell you than let a questionnaire surprise you.

ItemStatusDetail
Data Processing Addendum (GDPR / UK GDPR / PDPO)AvailableStandard Contractual Clauses incorporated; sub-processor list published
Sub-processor listPublished/legal/subprocessors
Hong Kong PDPOCompliantData user: Carnegie Intelligent Technology Limited
Encryption in transit / at restIn placeTLS 1.2+; Google-managed encryption at rest
Penetration testPlanned Q1 2027Third-party; summary available under NDA
SOC 2 Type IPlanned H1 2027Type II to follow after observation period
ISO 27001EvaluatingDependent on customer demand
Vulnerability disclosureLive[email protected]

Responsible disclosure

If you believe you have found a security vulnerability in Sparring, email [email protected] with steps to reproduce. We acknowledge within 2 business days, keep you informed, and credit you (if you wish) when the issue is fixed. Please do not access data that isn't yours, degrade the service, or disclose publicly before we have had a reasonable chance to remediate. We do not pursue legal action against good-faith research that follows these rules.

Incident notification

Confirmed incidents affecting your data are notified to your organisation owner within 72 hours of confirmation, with scope, impact and remediation — as required by our DPA.

Need a security questionnaire answered?

Send it. We answer in writing, usually within a week, and we'll tell you where we fall short rather than hedge.