← Back to MetricSpark
Trust · Security & Privacy

Security & Privacy

Last updated: 29 July 2026

MetricSpark is designed to sit quietly alongside your operations — reading the signals your team already produces and turning them into answers, without changing your systems or taking your data anywhere it doesn't belong. This page explains how the product is built and the principles we hold ourselves to.

Early-access note. MetricSpark is an independent product in early access. The practices below describe how the product is designed and operated. Formal third-party certifications (e.g. SOC 2) are on the roadmap, not yet in place — we'd rather tell you that plainly than imply otherwise.

1. Read-only by default

MetricSpark observes; it does not act on your systems. Connections to your source systems request read-only scopes wherever the platform supports them. The product does not create, edit, close, or delete records in your PSA or other tools — your source of truth stays exactly where it is.

2. Least privilege & scoped access

Each integration asks only for the narrowest set of permissions it needs to do its job. Access is scoped per connection and can be revoked by you at any time from the source system. We do not request broad administrative rights we don't use.

3. Your data stays yours

4. Encryption

Data is encrypted in transit using TLS, and encrypted at rest by the underlying cloud platform. Secrets and access tokens are stored in managed secret storage, never in plain text in application code or logs.

5. Data minimisation & retention

We keep only what a feature needs and no longer than necessary. Where the product can work from aggregates or recent windows rather than full history, it does. On account closure, connected-system data can be purged on request.

6. Authentication & access control

Sign-in supports single sign-on via Microsoft Entra. Access inside the product is role-based, so people see the views appropriate to their role. Administrative actions are limited to authorised users.

7. Hosting & infrastructure

MetricSpark runs on reputable managed cloud infrastructure with network isolation, automated patching, and platform-level protections. We rely on the provider's physical and infrastructure security controls rather than operating our own hardware.

8. Transparency & grounded answers

Every answer the AI gives is grounded in your own data and shows the numbers behind it — it does not invent figures. If the data to answer a question isn't available, the product says so rather than guessing.

9. Demo data on this website

Everything shown publicly on this website — screenshots, the interactive demo, and any sample deliverables — uses 100% synthetic, fictional data. It represents no real organisation, customer, or dataset.

10. Responsible disclosure

If you believe you've found a security issue, please email support@metricspark.info. We welcome good-faith reports and will work with you to confirm and address valid findings.

Questions about security or privacy? Email support@metricspark.info.

© 2026 MetricSpark · Aman Thakur · All rights reserved. MetricSpark is an independent product and is not affiliated with any employer or client.