Documentation
Compliance & Privacy
Learn how Specteron approaches privacy, regulatory alignment, vendor diligence, and controlled AI data processing.
GDPR & CCPA Support
Specteron is built to help customers operate under modern privacy requirements, including European and California data protection expectations.
- Data Subject Requests: Customers can handle access, deletion, and related privacy requests through product workflows and supported APIs.
- Consent-Aware Integrations: Widget and analytics behavior can be aligned with cookie and consent requirements on public websites.
- DPA & Transfers: A production DPA and the exact provider transfer safeguards are being verified. Contact support before relying on contractual coverage.
AI Compliance & Data Ethics
AI-assisted support requires disciplined controls around sensitive data, disclosure, and model usage. Specteron is designed with those constraints in mind.
- AI Provider Terms: OpenAI API data is processed under the provider’s current API terms and data controls. Users should avoid unnecessary sensitive data.
- Optional PII Controls: Teams can apply data-handling rules and redaction patterns before content reaches external intelligence layers.
- Transparent Subprocessing: Relevant subprocessors and hosting regions are documented so procurement and compliance teams can assess residency obligations clearly.
Current compliance status
Specteron is not presented as SOC 2 or ISO 27001 certified. Security and privacy controls are being documented and improved as the project develops.
- Continuous Monitoring: Operational controls, access hygiene, and infrastructure posture are monitored on an ongoing basis.
- Independent Review: No independent audit report is currently promised. Available technical information can be discussed through support. Reports.
Regulated data
Specteron is not currently offered as a default environment for regulated health data or other highly sensitive workloads.
- Business Associate Agreements: No BAA or HIPAA commitment is currently advertised.
- Sensitive Workloads: Do not upload regulated or highly sensitive data without a verified legal basis and confirmed contractual and technical safeguards.