The most useful thing Spengine does for your security is hold very little. There are no public accounts, so there is no password database, no session to hijack, and no profile to breach.
All traffic encrypted in transit over HTTPS (TLS)
No public sign-in, so no credentials of yours are stored anywhere
Analytics records carry no name, account, device or session identifier
We do not sell or share personal information
Infrastructure Security
Spengine runs on managed platforms rather than servers we operate: Vercel for hosting and Neon for the database. It inherits their infrastructure protections, including:
Redundant, backed-up managed Postgres storage
Platform-level DDoS protection at the network edge
Host and runtime patching handled by the platform
Credentials held as environment secrets, never in the codebase
There Is No Account To Secure
Spengine has no public sign-in, so there is nothing to log into and no password of yours for anyone to steal.
We will never email you asking for a password, a payment card, or account details. Anything that does is not from us
We will never ask you to “verify” or “reactivate” a Spengine account, because you do not have one
If you receive something claiming otherwise, report it through the contact form
Vulnerability Disclosure
We welcome security researchers to help improve our platform. If you discover a vulnerability, please report it responsibly through our contact form.
We respond to all reports within 48 hours
Incident Response
In the event of a security incident:
We will post what happened on this page, since a notice on the site is the only way we can reach visitors we hold no address for
Anyone who has contacted us, and whose message is affected, will be emailed directly
We will say what was involved and what was not, without waiting to know everything
Where the law requires a regulator to be notified, we will notify them