Security & Privacy
Your security, privacy, and safety is our top priority - and everything we do is focused on protecting it.

Trusted by
















Data Security
Encryption, management, and security
We implement comprehensive security measures to ensure your data is protected against unauthorized access, breaches, and other threats. We leverage best in class encryption, access controls, and intrusion detection software to safeguard your data. Our commitment to robust data security practices ensures that your information remains safe and confidential. See more details in our trust center.

AI Governance
Trust and Transparency
We prioritize responsible AI practices and never use your data to train AI models. Your privacy and trust are fundamental, and we follow strict guidelines to keep your information confidential and secure. We also enforce these requirements with all our AI subprocessors and require them to also enforce zero data retention policy on your data.

Privacy
Protecting your personal data
Spinach AI prioritizes your privacy through a comprehensive compliance program, adhering to industry best practices and regulations like GDPR. Our data governance ensures secure, accurate, and accessible data handling, from collection to deletion. We hold vendors to our high standards, detailed in regularly-reviewed agreements. Our transparent policies detail data handling and your rights, reflecting our commitment to data confidentiality and security through ongoing team training.

Compliance
Spinach maintains a comprehensive security and privacy program designed to protect your data. We receive regular independent third party audits. For access to our reports, please email security@spinach.ai.

SOC 2
Our SOC 2 Type 2 certification, verified by an independent auditor, EY, confirms that our security controls effectively protect your data over time. This ensures the security, reliability, data integrity, confidentiality, and privacy of your sensitive information. Please contact us to receive access to our SOC2 report.

GDPR
Our GDPR compliance, reflecting adherence to strict data protection regulations, confirms that we rigorously protect your personal information. This ensures responsible data handling, transparency, and the highest privacy standards, building trust and confidence. Please contact us regarding access to our DPA.

HIPAA
Our HIPAA compliance, reflecting adherence to U.S. federal law, and reinforced by signing Business Associate Agreements (BAAs), confirms we rigorously protect your protected health information (PHI). This ensures data confidentiality, integrity, and security, meeting stringent requirements for handling sensitive health information.