Security & Trust

“You, in the loop”is a guarantee, not a slogan.

Supasprinkles takes real actions across your business, so the question that matters isn't which badges we hold. It's what the agents can do, and whether you can see and stop them. Every mechanism on this page is the answer.

Scopes · approvals · the ceiling · reversibility · audit
Zero-trust architectureTenant-isolated infrastructureLeast-privilege accessContinuous monitoringEncrypted at every layer
You stay in control

What can each agent actually do?

Every agent runs under strict, revocable scopes. You decide how far each one can go, and you can see exactly what it's allowed to touch.

Scoped permissions per agent

Each agent only touches the tools and data you grant it.

Read-only vs action-enabled

Decide whether an agent observes, or observes and acts.

Human-in-the-loop approvals

Anything irreversible waits for your sign-off.

Rate-limited system actions

Hard ceilings on what agents can do in any window.

Continuous behaviour monitoring

Every agent is watched for drift from its scope.

Product ops operator
Scoped · revocable
Action-enabled
NotionRead
JiraWrite · needs approval
StripeNo access
Awaiting your approvalUpdate PROD-421
Rate limit · 40 actions / hour
The ceiling

Some things agents can never do.

Regardless of configuration, autonomy level, or who asks. These aren't settings, they're hard limits built into the platform.

Move money or change payment detailsDelete data, systems or environmentsMessage your customers without approvalGrant, change or escalate accessDisable their own audit logging
Reversibility

Slam the brakes. Undo anything.

The most important control isn't what an agent can do; it's that you can stop it instantly, and take any action back.

One-click pause

Freeze a single agent, a whole team, or every agent at once.

Roll back any action

Every change is reversible and restores the prior state.

Auto-pause on incidents

Conditional and scheduled pauses for risky windows.

Nothing irreversible without you

Destructive or costly actions always wait for approval.

Global agent control 6 agents active
Freezes every agent instantly. Resume the moment you're ready.
Rolled back · Jira PROD-421
Restored to previous state in one click
Reversible
Audit logging

Every action is fully traceable.

User, agent, workflow, integration and permission events, all captured, all explained in plain language.

Immutable Time-stamped Exportable

Complete forensic visibility for security, compliance and governance.

Audit stream Live
Nile Okafor approved a billing correction
User activity
2m
Product ops operator updated Jira PROD-421
Agent activity
14m
Release-readiness workflow executed
Workflow execution
1h
Salesforce connection read 38 records
Integration access
3h
Role changed: Maya → Admin
Permission change
5h
Your data stays yours

We never train on your data.

Not our models. Not anyone else's. Your operational data is used to run your operation, nothing more.

Never used for training

Your data never trains our models, or anyone else's.

UK & EU residency

Stored and processed in UK/EU regions, under UK GDPR.

Always yours

Export or erase your data at any time.

How your data is handled

Security by design, not by afterthought.

A security-first, zero-trust architecture: isolated, encrypted, and scoped to exactly what you allow.

Multi-tenant isolation

  • No cross-tenant data visibility
  • Enforced at the database policy level
  • Encryption boundaries per tenant
  • Dedicated audit streams per organisation
OutcomeYour data is never co-mingled. Ever.

Encryption everywhere

  • AES-256 encryption at rest
  • TLS 1.2+ encryption in transit
  • Encrypted secrets management
  • Secure API token storage
  • Automatic key rotation
OutcomeProtected at every step, stored, transmitted and processed.

You choose the access level

  • Read-only access
  • Event-based triggers
  • Full automation permissions
  • Revocable at any time
OutcomeTotal transparency over what Supasprinkles can access and do.
Permissions & access

Enterprise identity, built in.

  • Role-based access control (RBAC)
  • Fine-grained permissions, feature and data level
  • Multi-tenant access isolation
  • Multi-factor authentication (MFA)
  • Session management & device trust

Only the right people can see or change the right things, always.

Single sign-on
Microsoft Entra IDSSO
Google WorkspaceSSO
OktaSSO
SCIM provisioning available on Enterprise
Compliance-ready

Built for regulated environments.

We badge status honestly. The control mechanisms above carry the weight.

SOC 2
Built to SOC 2 controls · audit in progress
GDPR
UK & EU GDPR compliant
ISO 27001
On the roadmap
Data residency
UK / EU regions
Right-to-erasure & data export tooling included We're built to SOC 2 controls and progressing through formal certification, not yet certified.
Data residency & infrastructure

Resilient operations, even at scale.

Cloud-native, multi-region capable
Region controls for data residency (Enterprise)
Automated backups
Disaster recovery planning
High-availability design
Continuous uptime monitoring
DDoS protection
Automatic key rotation policies
We run on a small set of vetted cloud sub-processors. The current list and data-residency options are available in our trust centre on request.
Secure by default

Run autonomous operations
securely.

The power of AI automation, with the controls your security team demands, and the brakes you can hit any time.