Security
SparGrid handles your marketplace credentials, catalogue, and orders, so security is built in rather than bolted on. Connections are official and least-privilege, credentials are vaulted, your data is isolated, and every write to a channel is operator-approved and reversible.
Secure by design
SparGrid connects to each marketplace through its official OAuth flow and requests only the scopes it needs. Credentials are held in a managed secret vault, your data is isolated per tenant, and the detailed controls are shared during a security review.
Access & identity
- Official OAuth connections; least-privilege scopes per channel
- Role-based access and approval gates for your team
- Clear separation between recommendation, approval, and dispatch
Credentials & isolation
- Marketplace tokens held in a managed secret vault
- Per-tenant data isolation: never pooled across merchants
- Encryption in transit and at rest
Operational controls
- Reads by default; writes only after operator approval
- Kill-switch to halt all dispatch instantly
- Reversible actions with full change history
Audit & compliance
- Time-stamped audit trail for every action
- GDPR-aligned design; SOC 2 readiness roadmap
- ISO 27001-aligned controls
Website security
- HTTPS with modern security headers
- Strict Content Security Policy (CSP)
- Rate-limited public endpoints
Vulnerability disclosure
Report concerns via the contact form or at support@sparande.co.uk. Please do not include sensitive data in your report.
SparGrid is decision intelligence with operator-approved execution. Credentials, data isolation, and access controls are designed in, so automation never outruns your control.