Security
Last Updated: September 22, 2026
SpAItial Security
Updated: 22 September 2026
SpAItial Ltd builds world models that generate explorable 3D environments. This page describes the security commitments we make to the people and organisations who use the Services. It reflects what we operate today. Where something is in progress, we say so. This page is not a substitute for our Terms of Service or Privacy Policy. Enterprise customers may request a Master Service Agreement and Data Processing Agreement by emailing [email protected].
Reporting a vulnerability
Email [email protected]. We acknowledge reports within one business day and will keep you updated until the issue is resolved. Please give us a reasonable opportunity to remediate before public disclosure. When you can, include a description of the issue, the affected URL or component, and steps to reproduce it. We will not pursue legal action against researchers who report in good faith, avoid privacy violations and service degradation, and do not access or modify data belonging to others. We do not currently operate a public bug bounty and do not guarantee compensation for reports. Machine-readable contact details: /.well-known/security.txt.
Protecting your data
Encryption. Data is encrypted in transit (TLS 1.2 minimum) and at rest with AES-256 using Google-managed keys. Isolation. Customer records are separated per tenant by row-level security in our database, and customer content is stored under per-tenant paths. Access control. Staff access requires single sign-on through Google Workspace with multi-factor authentication enforced. Our internal and model-training infrastructure has no public ingress: administrative access is only possible over a private WireGuard network. Credentials are centralised in a managed secret store. Deletion. We delete customer data within 30 days of a verified request, including at our subprocessors. Requests go to [email protected] or through account settings.
Protecting the service
Perimeter. Public endpoints are served through Cloudflare with a web application firewall and DNSSEC enabled. Change management. Every infrastructure change ships as a reviewed, revertible commit. Automated static analysis gates merges on all of our product and infrastructure repositories. Vulnerability management. We run continuous dependency and code scanning and remediate on severity-based timelines: critical within 7 days, high within 30 days, medium within 90 days. Independent testing. We commission an independent third-party penetration test at least annually, and on significant changes to a critical application. Resilience. Production data is backed up daily to independent storage, with point-in-time recovery available on the customer database.
People and suppliers
Our staff complete security-awareness training and acknowledge our security policy set, on a 30-day service level. We maintain a register of the subprocessors that handle customer data and assess their security before onboarding.
Your responsibilities
You are responsible for protecting access to your SpAItial account, including passwords, single sign-on, and API keys; for deciding which Authorised Users may use the Services; and for notifying us promptly if you suspect unauthorised access. Do not share API keys or embed them in public repositories.
Incidents
If a personal-data breach occurs, we notify the relevant supervisory authority within 72 hours, as required by UK and EU GDPR Article 33, and we notify affected customers in line with their agreements.
Changes to these commitments
We review this page at least annually, and whenever a listed control changes. If we make a material change to these commitments we will update this page and, where the change is adverse, notify customers by email or an in-product notice, consistent with the change-notice clause in our Terms of Service. Related documents: Privacy Policy, Terms of Service, Cookie Policy, Subprocessors. For a security questionnaire, DPA, MSA, or questions about this page, contact [email protected].
