Security Policy
This Policy describes the technical and organizational measures Prestance Lab applies to protect Customer Data processed through the Services. It is referenced from Prestance Lab's General Terms and Conditions and from the Data Processing Agreement, and reflects the safeguards in place across our infrastructure, encryption, access-control, and AI processing layers.
1. Overview
Prestance Lab operates a multi-tenant Software-as-a-Service platform that processes voice and text data generated during sales-advisor rehearsal drills (simulated client conversations). This document summarizes the technical and organizational measures (the "TOMs") we apply to safeguard Customer Data, in alignment with the commitments set out in our General Terms and Conditions and our Data Processing Agreement.
2. Hosting and infrastructure
The Services are operated on independently audited, enterprise-grade infrastructure providers. Core infrastructure — database, application runtime, and media transport — is pinned to the European Union; the AI inference providers and their respective countries of processing are itemized below and in the DPA, §7.
- Database & backend
- EU-hosted PostgreSQL with daily encrypted backups and point-in-time recovery. Hosting region: Frankfurt (EU). Provider listed in the DPA, §7.
- Application backend
- EU-hosted application runtime serving the API, the voice-agent worker, and the manager dashboard. Hosting region: Paris (EU).
- Voice transport
-
WebRTC SFU operated in EU region (
eu-central), end-to-end-encrypted in transit via DTLS-SRTP. Provider listed in the DPA. - Real-time voice AI
- Live-drill voice-to-voice, coach, and intro-briefing voice synthesis run on our real-time voice provider's infrastructure in the United States (no EU data residency), accessed under a signed Enterprise Data Processing Agreement with Standard Contractual Clauses. Provider and transfer mechanism listed in the DPA, §7.
- Coaching-pipeline LLM & embeddings
- Open-weight model inference for post-drill analysis, accessed under a signed Data Processing Agreement. Processed in the United States under Standard Contractual Clauses by default, with an EU dedicated deployment available on request. Provider listed in the DPA, §7.
- Mobile application
- Flutter (iOS / Android). Runs on the Authorized User's device; no Customer Data is stored locally beyond authentication tokens.
Prestance Lab contracts only with sub-processors that hold independent third-party security audits. The complete sub-processor list — including entity name, country of processing, transfer mechanism, and DPA link — is maintained in the Data Processing Agreement.
3. Encryption
In transit
TLS 1.2 or higher is enforced on all application, database, and API connections. Voice sessions use WebRTC with DTLS-SRTP, providing end-to-end-encrypted audio transport between the advisor's device and the Prestance Lab worker.
At rest
All persistent data — database rows, object storage, backups — is encrypted using AES-256. Encryption keys are managed by the underlying hosting provider with HSM-backed rotation.
4. Access control
Prestance Lab enforces a three-layer access-control model:
- Application layer — role-based UI access (Advisor, Manager, Admin), enforced at the routing layer.
-
API layer — every endpoint requires a JWT
(
ES256, issued by Supabase Auth) and is validated against an explicit allow-list of claims. - Database layer — Row-Level Security (RLS) policies are applied on every table and enforce strict workspace and user isolation. No application path bypasses RLS.
Drill sessions are workspace-scoped: only the advisor themselves and the designated manager Authorized Users of that workspace can read drill transcripts, scores, and coaching letters via the manager dashboard. No Outputs are exported to the Customer's HR systems by Prestance Lab.
HR use of Outputs is restricted
Per-advisor Outputs are surfaced to designated manager Authorized Users by design. The Customer is responsible for ensuring those Outputs are not used as the sole or principal basis for any HR decision, as the basis for automated decision-making within the meaning of Article 22 GDPR, or to infer special-category data within the meaning of Article 9 GDPR. The substantive prohibition is set out in our Acceptable Use Policy §4.
5. AI and data privacy
No training by sub-processors on Customer Data
All AI sub-processors that process Customer Data are accessed via paid Enterprise tiers under explicit no-training contractual terms in their respective Data Processing Agreements — for example, the Google Cloud Service Specific Terms, under which Customer Data is not used to train Google's foundation models, governing the real-time voice provider; and the Fireworks Privacy Policy "No AI Training on Your Data" clause, governing the coaching-pipeline provider. OpenAI processes no Customer Data: it is used only as an eval judge over synthetic test fixtures, as recorded in the DPA, §7.
Temporary retention for abuse monitoring
Temporary retention for abuse monitoring at the provider level may apply (typically ≤ 30 days). Sub-processors may apply human review to content flagged by automated abuse-monitoring systems, in accordance with each provider's published policy. Prestance Lab does not control this review and surfaces the relevant provider policies in the DPA.
Voice recordings
Voice recordings are created by Prestance Lab's worker via the LiveKit Egress API and uploaded directly to a Prestance Lab-controlled storage bucket. Recording retention is governed by the Customer's Order Form and the Data Processing Agreement. Anonymization of voice recordings (speaker de-identification at rest) is in design and will be rolled out as a separate release; it is not in effect for v1.
Data residency
Core infrastructure data paths are pinned to EU regions: Supabase
Frankfurt (database, authentication, object storage), Fly.io Paris
(application and voice-agent worker), and LiveKit
eu-central (Frankfurt, media transport). Two AI
processing activities take place in the United States under Standard
Contractual Clauses: real-time voice synthesis (the live-drill
voice-to-voice, coach, and intro-briefing provider), with no EU data
residency; and post-drill coaching analysis, processed in the United
States by default, with an EU dedicated deployment available on
request. A limited set of observability and abuse-monitoring metadata
may additionally transit to the United States at the vendor level. The
provider, country of processing, and transfer mechanism for each are
disclosed in the
Data Processing Agreement, §7.
6. Data ownership and retention
- The Customer remains the holder of all rights, title, and interest in and to Customer Data, in accordance with GTC §2.5.
- Prestance Lab processes Customer Data solely to provide the Services and as further described in the Data Processing Agreement.
- Aggregated or anonymous usage metrics may be used to operate, secure, and improve the Services in accordance with GTC §2.5; no personal data or Confidential Information is used for this purpose.
- Session data — transcripts, scores, and coaching letters — is deletable on Customer request, either via the manager dashboard or by emailing privacy@sparred.ai.
- On termination of the Agreement, all Customer Data is permanently deleted within 30 days, save for backups which are purged on the next scheduled rotation (90 days maximum).
7. Sub-processors
The complete list of sub-processors, including activity, country of operation, and transfer mechanism, is maintained in the Data Processing Agreement. Changes to the list are notified to active Customers in accordance with the procedure described therein.
8. Operational security
Account hygiene
All Prestance Lab corporate accounts use multi-factor authentication. API keys are rotated quarterly and on personnel change.
Personnel and contractors
Prestance Lab maintains an internal Acceptable Use Policy binding all employees, interns, and contractors with access to Prestance Lab systems, code, or Customer Data. It covers device security, credential handling, approved tooling for work on Customer Data, and offboarding. Contractors acknowledge it in writing as a condition of access and remain subject to it for the duration of the engagement.
Secrets management
Production secrets are stored in the hosting provider's managed secret store and never committed to source control.
Patching
Application dependencies are scanned weekly. Critical vulnerabilities are patched within 7 days of public disclosure.
Backups
PostgreSQL backups are taken daily and stored encrypted, with a retention period of 30 days. Point-in-time recovery is available to a granularity of 5 minutes within the preceding 7 days.
Incident response
A documented runbook covers detection, containment, eradication, recovery, and post-incident review. Personal Data Breaches are notified to the Customer without undue delay, in accordance with the Data Processing Agreement.
9. Compliance posture
GDPR
Compliant. EU hosting is in effect; a Data Processing Agreement is executed with each Customer; sub-processor DPAs are in place; Standard Contractual Clauses apply to any non-EU sub-processor transfer.
EU AI Act
Prestance Lab acts as the provider of the Solution within the meaning of the EU AI Act and complies with the provider obligations under Articles 25 et seq. The Solution does not perform emotion recognition in the workplace within the meaning of Article 5(1)(f).
SOC 2
Prestance Lab's own SOC 2 Type I observation period is underway. All infrastructure sub-processors are independently SOC 2 certified.
10. Reporting a security concern
- Email security@sparred.ai.
- We will acknowledge receipt within 1 business day and provide updates as the investigation progresses.
- Coordinated disclosure: please allow a reasonable window for remediation before any public disclosure.
11. Updates to this Policy
In accordance with GTC §2.7, Prestance Lab may update this Policy. Material changes will be notified to active Customers at least 30 days in advance, unless a shorter timeframe is required by law or to address a material security risk.