The org chart that draws itself. Live demo, no sign-up.Play with it →
Trust

Trust & Security

Sprooster holds a copy of your organization's directory, so you deserve to know exactly how it's treated. These are the commitments our privacy policy makes, and the controls behind them.

Our commitments

Enforced in code

These commitments are wired into our engineering process, not filed away in a policy document. An automated check suite runs against every change and fails the build if a change would enable session recording, put personal data into analytics events or error reports, or add a table holding personal data without covering it in workspace export and deletion. The deletion and export paths are derived from the database schema itself, so new data cannot silently fall outside them.

Product security

Sub-processors

The vendors that process personal data on our behalf are listed at /legal/subprocessors, where organizations can subscribe to be notified before the list changes.

Certifications and questionnaires

We do not yet hold a SOC 2 or ISO 27001 certification, and we won't claim one here until we do. In the meantime we're glad to complete security questionnaires and walk your team through our architecture and controls, and a Data Processing Agreement is available to customer organizations on request. The contact details are in our privacy policy.