Trust and security
SpanDock is self-hosted: your telemetry is received, stored and shown on your own machines. This page sums up how it’s protected, what reaches us, and where our security and compliance work stands.
In one page
- Your data stays with you. Telemetry, prompts, code and tool output never reach spandock.com. They go only to the destinations you add.
- Encrypted in transit. Clients reach servers over an encrypted WireGuard tunnel, or over HTTPS through the optional public endpoint. This website is HTTPS only, with HSTS.
- Secrets in the OS credential store, or a file only the service can read. Tokens and API keys are stored only as hashes.
- Nothing exposed by default. The dashboard listens only on the machine itself. Remote access needs an approved client, and remote management also needs a management token.
- Signed licenses. License keys are signed with Ed25519, so a server can verify its license offline.
What stays where
Your servers keep your telemetry in an embedded database on their own disks, and forward it only to the destinations you configure. spandock.com receives two things: license checks from your server (a random installation ID, the role, version, operating system, and counts of active clients, servers and satellites), and account and billing data when you sign up and subscribe.
The details, including every network request the app makes, are in Privacy and security and Licensing and activation.
Encryption
- Between your machines: a WireGuard tunnel between clients and servers, with no open ports. The optional public endpoint uses HTTPS with certificates the server obtains and renews itself.
- On your machines: your data lives on your disks, under your operating system’s protection. Use disk encryption for data at rest, as for any server.
- On spandock.com: HTTPS only (with HSTS), and account data in a managed database encrypted at rest.
Sign-in, SSO and MFA
- Server dashboards are reached on the server itself, or through an SSH tunnel. Signing in with your spandock.com account, and company single sign-on (OIDC or SAML) on the Enterprise plan, are coming to the dashboard.
- spandock.com accounts sign in with a one-time code sent by email, a passkey, or Google or GitHub, and can add an optional password. Anyone can add a passkey or an authenticator app (with backup codes) and ask for that second step after every sign-in. Our own staff console always requires it.
Compliance status
We don’t hold certifications yet. This is the honest status, updated as each step completes.
| Item | Status | Notes |
|---|---|---|
| Independent penetration test | Planned | The server, the dashboard and this website's license service. We'll publish a letter here once the high findings are fixed. |
| SOC 2 Type II (Security) | Planned | After the penetration test, with a three-month observation window. |
| Data processing agreement (DPA) | In preparation | Being drafted with counsel. Until it's published, ask us for the current terms. |
| Subprocessor list | In preparation | Published with the DPA. Until then, ask us for the current list. |
For the DPA, the subprocessor list or a security questionnaire, write to privacy@spandock.com.
Report a security issue
Write to security@spandock.com with what you found and how to reproduce it. Please give us a chance to fix it before you share it publicly. We’ll acknowledge your report and keep you updated until it’s resolved.
If a security incident affects your data, we’ll tell you what happened, what it affects and what we’re doing about it, without undue delay. The exact terms will be in the DPA.