What standards we meet, what we're working on, what we don't claim
Spun is built with privacy and security by design. We use encryption in transit, controlled access, audit logging, configurable data retention, and customer-controlled AI features. We do not overclaim — every status below is current.
Status by standard
Where we stand
Every standard below is shown with current status. If a status is "In progress" or "Roadmap," ask us for the latest milestone.
SOC 2
What it is
AICPA framework covering security, availability, confidentiality, processing integrity, and privacy controls for service organizations. Type I is point-in-time; Type II is over a 6–12 month period.
Our position
SOC 2 readiness program in progress: access logging, change-management, vendor review, vulnerability scanning, incident response, employee access policy, and least-privilege controls are all in place. Type I attestation targeted for the second half of 2026; Type II to follow once we have operational history.
GDPR (EU/EEA)
What it is
EU regulation governing personal data of EU/EEA residents. Spun typically acts as a data processor; the customer is the controller of their end-user data.
Our position
GDPR-aligned controls in place: lawful basis documentation, DPA available on request (with EU Standard Contractual Clauses for international transfers), published sub-processor list, data minimization defaults, retention controls, customer-controlled export and deletion, AI processing disclosure, and breach-notification procedure within the 72-hour requirement.
ISO/IEC 27001
What it is
International standard for information security management systems (ISMS). Widely recognized for enterprise / international procurement.
Our position
On the roadmap after SOC 2 Type II. Many of the underlying controls overlap with our SOC 2 readiness work, so the incremental effort is significant but not green-field.
EU AI Act
What it is
EU regulation in force since 1 August 2024, with most rules applying from 2 August 2026. Risk-tiered obligations: prohibited / high-risk / limited-risk / minimal-risk AI systems.
Our position
Spun's AI features (compose, summarize, transcribe, translate, smart replies, classification) are limited-risk by default — used for general business communication, not high-stakes decisions about people. We provide AI-usage disclosure, customer toggles per feature, audit logging (optional), human-approval modes, no training on customer data, vendor disclosure, and PII redaction before AI processing. If you are using Spun in a use case that becomes high-risk under the Act (hiring decisions, credit, health, education, legal advice, biometric ID), contact us.
Israeli Privacy Protection Law (Amendment 13)
What it is
Israel's privacy law modernized in 2024 (effective August 2025), bringing it closer to GDPR-style obligations.
Our position
Spun's GDPR-aligned controls cover most of the core obligations under the updated Israeli law. Database registration: Spun stores customer contact data only to provide the SaaS workspace to each customer — we do not sell, broker, transfer, or independently use customer contact lists. Contact data remains logically separated by organization (RLS-enforced). Spun is not a public body. Under Amendment 13, registration mainly applies to public-body databases and data-broker/direct-mailing databases exceeding 10,000 records; our processor-only model does not trigger registration at launch. We will reassess if Spun offers large-scale direct-mailing/broadcast services, combines contact lists across customers, or transfers contact data beyond listed sub-processors. Hebrew-language privacy materials and DPO designation (if required at scale) are in progress.
Data retention
Retention limits per plan
Older messages automatically prune at the plan limit. You can tighten retention further per-chat in Safety & Privacy → Message Storage Limit, or wipe everything on demand.
| Plan | Message history | Media storage |
|---|---|---|
| Free Trial7-day trial | 30 days | 5 GB |
| Basic | 90 days | 10 GB |
| Pro | 1 year | 75 GB |
| Power | Unlimited | 500 GB |
On account deletion, all personal data is removed or anonymized within 30 days, except where retention is required by law (financial records, fraud prevention).
Where your data lives
Regional hosting
All application servers and the database live in a single EU data center. The marketing site and media files are served globally from Cloudflare's edge network for low latency everywhere.
Hetzner Nuremberg
EU (Germany) — application servers + PostgreSQL
The single data tier. All application servers, database, and Redis run here. AES-256 encrypted disks.
Cloudflare Pages
Global edge — marketing site & static assets
spun.com and 20+ regional domains served from Cloudflare's global edge network. Visitors get the nearest PoP automatically.
Cloudflare R2
Global — images, video, file attachments
All media (images, video, audio, documents) stored in R2 with AES-256 at rest. Access gated by per-org, per-object signed URLs.
Israel region
Israel
Under evaluation for Israeli market expansion. Currently Israeli customers are served from Hetzner Nuremberg (EU).
India region
India
Under evaluation for Indian-language voice features and data residency.
Where we sell, and why
International launch roadmap
We launch in markets where WhatsApp is core business infrastructure first, and expand to higher-compliance enterprise markets as our certification matures.
- 1
Israel & Latin America (current)
Israel (Hebrew + English UI, GDPR-aligned). Mexico, Colombia, Argentina, Chile, Peru, UAE — WhatsApp is universal business infrastructure, sales cycles are short. SOC 2 readiness sufficient.
- 2
US SMBs (current, expanding)
Home services, real estate, e-commerce support, travel, education, wellness. SOC 2 Type I and a complete DPA package make Spun viable for most US SMB and mid-market buyers.
- 3
EU & UK enterprise (after SOC 2 Type I)
Enter once SOC 2 Type I is signed and ISO 27001 work is underway. Requires polished DPA + SCCs, EU hosting confirmation, and full deletion/export tooling — all of which are in place but benefit from third-party attestation before larger enterprise sales.
Documents available
Request from [email protected]
Data Processing Agreement (DPA)
GDPR-aligned, includes EU Standard Contractual Clauses for international transfers.
Sub-processor notification list
Get email updates when we add or change a sub-processor.
Security overview
Architecture, encryption, access control, vulnerability management.
AI data processing policy
Which AI vendors, what data they see, no-training commitment.
Incident response policy
Detection, containment, customer notification timelines.
Acceptable Use Policy
What is permitted on Spun and the basis for enforcement.
Have a security questionnaire?
We respond to standard security questionnaires (SIG, CAIQ, custom enterprise) within 5 business days. Email [email protected] with your timeline.