Trust & Transparency

Your Data, Protected

We built SpreadAPI with a simple principle: collect only what's essential, protect everything we touch, and give you full control over your data.

Built on SOC 2 Type 2 Infrastructure
ISO 27001 Certified Providers
TLS 1.3 Encryption
GDPR Compliant
Our Philosophy

Less Data, More Security

The best way to protect data is to not collect it in the first place. Here's what makes SpreadAPI different.

Email Only

We store just your email address. No names, phone numbers, addresses, or tracking data.

15-Minute Cache

Calculation results are cached briefly for performance, then automatically deleted. We don't keep your query data.

Formulas Stay Private

Your Excel formulas are never exposed. The API returns results only—your business logic remains yours.

Infrastructure

Built on Trusted Foundations

We chose infrastructure providers with rigorous security certifications so you benefit from their enterprise-grade security controls.

Vercel

Application hosting with global edge network. Enterprise hosting available for customers with stricter requirements.

SOC 2 Type 2ISO 27001GDPR

Redis Cloud

Database for metadata and caching

SOC 2 Type 2ISO 27001ISO 27017ISO 27018

Hanko

Passwordless authentication

FIDO AllianceFIDO2 CertifiedOpen Source
Authentication

Phishing-Proof Login

We use passkeys instead of passwords. Your credentials are stored on your device, not our servers—making phishing attacks impossible.

  • No passwords to steal or guess
  • Passkeys only work on legitimate domains
  • Cryptographically secure, device-bound
Encryption

Protected Everywhere

Your data is encrypted in transit and at rest. API tokens are hashed—we never store the actual values.

  • TLS 1.3 for all connections
  • AES-256 encryption at rest
  • SHA-256 hashed API tokens
Compliance

Meeting Your Requirements

GDPR

Full GDPR compliance with data minimization, right to erasure, and data portability. DPA available upon request.

Healthcare & Regulated Industries

Need HIPAA? We offer Enterprise hosting on HIPAA-ready infrastructure, or On-Premises deployment in your own compliant environment.

Certified Providers

All our infrastructure providers (Vercel, Redis Cloud) maintain SOC 2 Type 2 and ISO 27001 certifications with annual third-party audits.

Maximum Control

Need Complete Data Sovereignty?

Deploy SpreadAPI Runtime in your own infrastructure. Zero external connections, air-gap compatible for runtime execution, no vendor access to your data.

Your Infrastructure
Data never leaves your network
Air-Gap Ready Runtime
No internet connection required for execution
Zero Vendor Access
Full control, full privacy

Questions About Security?

We're happy to discuss your specific requirements, provide compliance documentation, or arrange a security review.