Skip to main content

Trust

How this is built, and who touches your data.

The documents a procurement team asks for, in one place. If your assessment needs something that is not here, ask and we will answer it in writing.

Security posture

  • Static output. No application server and no database in the request path on a published site.
  • No admin login exposed on a client site, so there is no credential to phish and no session to steal.
  • A content security policy built with each page, so anything injected afterwards is refused by the browser.
  • Tenant isolation enforced by infrastructure policy, beneath the application, with credentials issued per request and expiring in minutes.
  • Every change is version controlled and passes a gate covering accessibility, contrast, performance, headers, links and structured data before it publishes.
  • Multi-factor authentication required on every account with access to client data.

Documents

Sub-processors

Who processes data on our behalf, and what each one does.

Privacy policy

What we collect, who it reaches, how long it is kept.

Cookie policy

Everything this site asks your browser to store, which is one item.

Architecture

For whoever is filling in the security questionnaire.

Reporting a vulnerability

Send it to security@webspark.app. We will acknowledge within two business days and tell you what we intend to do. We will not pursue anybody who reports a genuine issue in good faith.