Loading
Loading
Your feedback directly shapes Sporos.
Sign in to track your feedback history
Security & data handling
This page lists what the system does today — and labels what is roadmap as roadmap. If a claim here matters to your review, ask us to demonstrate it: talk to us.
Your questions, watchlists, stance text, and generated artifacts are never used to train models — ours or anyone else's. Model calls run against frontier APIs under enterprise terms that exclude training on inputs.
The corpus is public government data — legislation, regulations, dockets, disclosures. The analyst works without ingesting your documents, so the highest-risk data class in most AI deployments simply isn't present.
The retrieval engine SELECTs against the corpus; it never writes to the record. The single write path is the run audit trail, and clients cannot forge it — writes happen server-side only.
Every user-owned row — runs, watchlists, account data — is guarded by database row-level security keyed to the authenticated user. Isolation is enforced in the database, not just the application.
TLS 1.2+ on every connection; AES-256 at rest on managed infrastructure (Vercel, Supabase/AWS).
Every signed-in run stores its full artifact with a SHA-256 content hash and the verification result it shipped with — who ran what, when, against which evidence. Deleting your account deletes your runs.
We publish our evaluation methodology and measured citation-faithfulness numbers — including the failures — with the harness committed to the repository. Security review gets receipts, not adjectives.
Retrieved text is treated as quoted data, never instructions, across the analyst and its verification pass — with guards at every model boundary.
Labeled honestly
The verification methodology and measured numbers live at /analyst/trust. Data-handling questions: contact us — security questionnaires answered directly for pilot customers.