Overview
Enterprise security is an important consideration when organizations use SPRL to manage links, domains, analytics, marketing workflows, APIs, and business data.
SPRL follows security-focused practices across its platform, infrastructure, application, access management, data protection, and operational processes to help protect customer information and maintain reliable services.
Good to Know:
Security is a shared responsibility. SPRL maintains platform and infrastructure safeguards, while customers are responsible for protecting their account credentials, API keys, user access, and the information they submit or process through the platform.
Security by Design
Security considerations are incorporated into the design and operation of the SPRL platform. Controls are applied across different areas of the platform to reduce the risk of unauthorized access, misuse, data exposure, and service disruption.
- Secure application design and development practices.
- Access controls for platform and infrastructure resources.
- Secure communication between users and SPRL services.
- Monitoring and operational safeguards.
- Security-focused handling of customer information.
- Processes for identifying and responding to security issues.
Data Protection
SPRL takes reasonable organizational and technical measures to protect information processed through its services against unauthorized access, alteration, disclosure, loss, or destruction.
Data protection practices are supported by SPRL's Privacy Policy and, where applicable, its Data Processing Agreement for enterprise customers.
- Controlled access to customer information.
- Protection of data during transmission.
- Security controls around application and infrastructure access.
- Operational procedures for handling security-related events.
- Privacy and data protection documentation.
Encryption & Secure Communication
SPRL uses HTTPS and TLS-based secure communication to protect information transmitted between users and SPRL services.
Secure communication helps protect information from interception or unauthorized modification while it is transmitted over the network.
| Area | Protection |
|---|
| Website Access | HTTPS-secured communication. |
| API Communication | Secure communication over HTTPS. |
| Authentication | Protected account authentication mechanisms. |
| Data Transmission | Encrypted communication between supported client and server connections. |
Account & Access Security
Protecting account access is an important part of maintaining a secure SPRL environment.
Customers should ensure that authorized users maintain secure credentials and that access is removed when it is no longer required.
- Use strong and unique account passwords.
- Never share account credentials with unauthorized individuals.
- Review user access periodically.
- Remove access that is no longer required.
- Keep account recovery information secure.
- Contact SPRL if unauthorized account activity is suspected.
Security Reminder:
SPRL will not ask customers to publicly disclose passwords, API keys, authentication credentials, or other sensitive security information.
API Security
Organizations integrating SPRL with their applications should treat API credentials as sensitive information.
API keys should only be provided to authorized applications and should be stored using appropriate security controls.
- Keep API keys confidential.
- Do not include API keys in publicly accessible source code.
- Do not expose API credentials in client-side applications where they can be extracted.
- Store credentials securely within your application environment.
- Review integrations periodically.
- Deactivate or replace credentials that are no longer required.
Important:
If an API key or other credential may have been exposed, take immediate steps to secure the affected integration and contact SPRL support where assistance is required.
Infrastructure Security
SPRL operates its platform using secured server and infrastructure environments with controls designed to protect applications, systems, and customer information.
Infrastructure security includes access controls, network protections, system administration practices, monitoring, and operational safeguards.
- Controlled infrastructure access.
- Network-level security controls.
- System and application monitoring.
- Security updates and maintenance.
- Operational access controls.
- Infrastructure-level safeguards against unauthorized activity.
Application Security
Application security is incorporated into the development and maintenance of SPRL services.
Security controls are applied to areas such as authentication, authorization, input handling, data processing, API access, and application operations.
- Input validation and request handling.
- Authentication and authorization controls.
- Secure API access practices.
- Protection against common application misuse.
- Security-focused application maintenance.
Monitoring & Abuse Prevention
SPRL uses operational monitoring and abuse prevention processes to help identify suspicious activity, misuse, security threats, and violations of platform policies.
These processes help protect the SPRL platform, customers, and the wider internet ecosystem from malicious or abusive use.
- Monitoring for suspicious platform activity.
- Abuse detection and investigation.
- Protection against malicious use of platform services.
- Investigation of reported abuse.
- Account or resource restrictions where required by policy.
Report Abuse:
If you identify a suspicious or abusive SPRL link, use the SPRL Abuse Reporting process to submit the relevant information for review.
Security Incident Response
SPRL maintains processes for identifying, investigating, and responding to security-related incidents and reports.
When a security issue is identified, appropriate actions may include investigation, containment, remediation, monitoring, and other measures necessary to protect the platform and affected services.
- Security issue identification.
- Investigation and assessment.
- Containment and remediation.
- Service and infrastructure monitoring.
- Follow-up actions where appropriate.
Responsible Disclosure
SPRL encourages responsible reporting of security vulnerabilities that may affect its websites, applications, APIs, or services.
Security researchers and other parties can report potential vulnerabilities through the security contact information published by SPRL.
- Provide sufficient information to reproduce the issue.
- Include the affected URL, endpoint, or component where applicable.
- Describe the potential security impact.
- Avoid accessing, modifying, or disclosing customer data.
- Allow SPRL reasonable time to investigate and address the issue.
Security Contact:
Security vulnerabilities can be reported to reportspam[@]insprl.com. Please do not include passwords, API keys, or unnecessary sensitive customer information in your report.
Security Policies & Documentation
Enterprise customers can review SPRL's published policies and documentation to understand the platform's approach to security, privacy, acceptable use, and data protection.
| Resource | Purpose |
|---|
| Security Policy | Provides information about SPRL's security practices and safeguards. |
| Privacy Policy | Explains how personal information is collected, used, stored, and protected. |
| Data Processing Agreement | Provides enterprise data processing terms where applicable. |
| Acceptable Use Policy | Defines permitted and prohibited uses of SPRL services. |
| Abuse Reporting Policy | Explains how abuse and harmful content can be reported. |
| API Terms of Use | Defines requirements for using SPRL APIs. |
Customer Security Responsibilities
Enterprise security is a shared responsibility. Customers should maintain appropriate security controls within their own organization when using SPRL.
- Protect account credentials.
- Manage user access appropriately.
- Protect API keys and integration credentials.
- Use secure devices and networks to access the platform.
- Review connected applications and integrations.
- Report suspected unauthorized activity promptly.
- Follow SPRL's published policies and terms.
Enterprise Security Checklist
| Security Area | Recommended Action |
|---|
| Account Security | Use strong credentials and protect account access. |
| User Access | Review authorized users and remove unnecessary access. |
| API Security | Store API credentials securely and review integrations. |
| Custom Domains | Maintain secure DNS and domain configurations. |
| Data Protection | Review applicable privacy and data processing requirements. |
| Monitoring | Monitor your organization's platform activity and integrations. |
| Incident Response | Report suspected security issues or unauthorized activity promptly. |
| Policies | Review SPRL security, privacy, acceptable use, and API policies. |
Frequently Asked Questions
Does SPRL encrypt data?
SPRL uses HTTPS and TLS-based secure communication to protect information transmitted between users and SPRL services.
Does SPRL provide an Enterprise Data Processing Agreement?
Yes. SPRL provides a Data Processing Agreement for enterprise customers where applicable.
How can I report a security vulnerability?
Potential security vulnerabilities can be reported through the security contact information published by SPRL. You can also review the SPRL Security Policy and responsible disclosure information.
How should I protect my API keys?
API keys should be treated as confidential credentials and stored securely. They should never be exposed in public repositories, client-side code, or publicly accessible documentation.
What should I do if I suspect unauthorized access?
Secure the affected account or credentials immediately and contact SPRL support with relevant information about the suspected activity.
Where can I find more information about SPRL security?
Visit the SPRL Trust Center for additional information about security, privacy, data protection, responsible disclosure, and related trust resources.
Quick Reference
| Area | Summary |
|---|
| Secure Communication | HTTPS and TLS-based communication are used to protect data in transit. |
| Data Protection | Organizational and technical safeguards are used to protect customer information. |
| Account Security | Customers should protect credentials and regularly review access. |
| API Security | API credentials should be securely stored and protected. |
| Infrastructure | Infrastructure access, network protections, monitoring, and operational safeguards are applied. |
| Abuse Prevention | Platform activity is monitored for suspicious and abusive use. |
| Responsible Disclosure | Security vulnerabilities can be reported through SPRL's published security contact. |
| Trust Resources | Security, privacy, DPA, acceptable use, and abuse reporting documentation is available. |
Learn More:
Visit the SPRL Trust Center and explore the Security Policy, Privacy Policy, Data Processing Agreement, Acceptable Use Policy, Abuse Reporting Policy, and API Terms of Use for additional information.
Tip: Enterprise customers should review their organization's security requirements before deployment and establish clear processes for account access, API credentials, custom domains, integrations, and security incident reporting.