SOC2C

Spline Inc security & compliance

An overview of Spline Inc's security posture — compliance, penetration testing, subprocessors, and data handling — verified on SOC2C (Listed).

SOC 2 statusSOC 2 Type II · Listed
FrameworksSOC 2 Type II, SOC 2 Type I, ISO 27001, GDPR
Penetration testNot listed
Subprocessors6 listed
HostingAWS
Trust centerView

Security questions about Spline Inc

Is Spline Inc secure?
Security isn't a single yes/no, but Spline Inc is SOC 2 Type II compliant and holds SOC 2 Type II, SOC 2 Type I, ISO 27001, GDPR, and undergoes third-party penetration testing. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Spline Inc have a bug bounty or vulnerability disclosure program?
Spline Inc hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@spline.design or via a /security page (Spline Inc lists a security contact).
Who are Spline Inc's subprocessors?
Spline Inc lists 6 subprocessors on its trust center, including Amazon Web Services, Metabase, Amplitude, Baremetrics, Github. Buyers use this for fourth-party risk review.
Where does Spline Inc host or store data?
Spline Inc hosts on AWS, and handles Customer personally identifiable information, Employee personally identifiable information, Credit card information, Personal health information. Data residency details are on its trust center.
Does Spline Inc offer a Data Processing Agreement (DPA)?
Spline Inc publishes a DPA on its trust center. You can request access through SOC2C.
Where is Spline Inc's trust center or security page?
Spline Inc's trust center is at https://trust.spline.design. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.

See Spline Inc's full SOC 2 profile →