TRUST CENTER
Trust Center
Spock is operated by Seleya Labs Inc. Our Terms, Privacy Policy and DPA contain the authoritative legal terms and disclosures. This page summarises processing facts; it is not a certification or a substitute for a customer-specific assessment.
Processing facts
Spock can route work automatically between its own models and external model APIs, and use separate providers for embeddings, images, transcription and tools. A manual model choice is not the only provider disclosure. Choosing an own/Spock model does not alone establish EU-only processing.
Observed infrastructure includes a Frankfurt DigitalOcean database endpoint, an AWS S3 bucket in Frankfurt and Cloudflare R2 buckets with Western Europe placement. R2 placement is distinct from EU jurisdiction. Other server, backup, machine and current GPU locations need service-specific confirmation.
Seleya is a US company. Our personnel work in South Africa and have access to production/customer content. TTL, its wholly owned SA subsidiary, invoices Enterprise customers; personnel engaged through TTL may perform authorised service work. Regional commitments must cover compute, storage, tools, backups and human access.
Contractual safeguards
- No training on Customer Content: the Terms and DPA prohibit Seleya and its subprocessors from using content to train, fine-tune or develop models, with the DPA breach remedy preserved. This does not mean zero storage or zero provider safety monitoring.
- Customer processing: the DPA covers instructions, confidentiality, appropriate security, rights assistance, incidents, audits, subprocessors, return/deletion and lawful transfers.
- Incidents: GDPR processor notice is without undue delay; applicable POPIA operator escalation is immediate. A GDPR authority deadline does not justify delaying customer notice.
- Subprocessor changes: the DPA provides advance notice to designated customers and an objection/remedy process. Updating this page alone is not notification.
Recipients and persistence
The single recipient/location schedule in DPA Annex B distinguishes infrastructure, model APIs, machines/web tools, payments, support, notifications, channels, connected accounts and corporate access. Not every listed recipient is active for every customer. Provider names and public terms do not prove account-specific acceptance or safeguards.
Memory files, generated artifacts, machine files and browser profiles can persist separately from a conversation. Stopping a task does not necessarily erase those copies or sign out a hosted browser. The Privacy Policy explains retention criteria and requests. No uniform 30-day AI-provider or 90–180-day application-log promise is made.
International safeguards
The DPA transfer provisions require an applicable lawful mechanism for restricted transfers and POPIA section 72(1)(a) protections where the binding-agreement route is used. We do not claim that a public SCC reference is a completed customer/vendor instrument, or that every account-specific transfer assessment has been verified.
Request information or legally available copies of the safeguards relevant to your service from support@spock.chat. Necessary redactions may protect other people’s information, confidential terms and security. A regional or sensitive-data deployment requires review of its actual destinations, recipients, contracts and controls before commitment.
Security information
The service uses HTTPS/TLS and password hashing. The DPA security schedule identifies required safeguards; assurance evidence must match the specific layer and service. We do not claim TLS 1.3-only operation or a completed Spock SOC 2 audit. A vendor’s certification applies only to its certified scope.
Vulnerability disclosure
Report suspected vulnerabilities to louis@spock.chat, copying support@spock.chat. Provide a minimal description and reproduction steps; avoid attaching customer content, credentials or a complete data dump. The reporting contact is also available in security.txt.
Use accounts and data you control. Do not access another person’s content, retain or disclose data encountered accidentally, disrupt availability, use social engineering or test third-party services without their permission. Stop and report if a test risks those effects.
For good-faith research within this scope, Seleya authorises the necessary limited testing of its own service and will not initiate legal action for that authorised activity. This does not grant permission over third-party systems or bind others. We will investigate reports and coordinate disclosure; no fixed acknowledgement time or paid bounty is promised.
Inventory update history
- 1 October 2026, version 3.0: corrected routing/location, retention, access and assurance descriptions; added AWS, R2, GPU infrastructure, Firebase and channel/affiliate qualifications; consolidated the recipient inventory in DPA Annex B and AI terms in the Terms/Privacy documents. This records disclosure corrections and does not assert that all recipients were newly introduced on this date.
- 1 August 2026: the previous published inventory and assurances are preserved in the legal archive.
Contact
Seleya Labs Inc. · support@spock.chat · Privacy and security contact: Louis-Neil Korsten, louis@spock.chat. Mailing address: 1111B S Governors Ave STE 56751, Dover, DE 19904, USA.