By clicking “Accept All Cookies”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. View our Privacy Policy for more information.
When partnering with SPREAD, you can be assured of the highest security and privacy standards. Discover how your information and data are safeguarded, giving you the peace of mind and trust you need to focus on what you do best.
Data protection that goes beyond industry standards
Trusted Information Security Assesment Exchange
The Trusted Information Security Assessment Exchange (TISAX) is a standardized information security model for the automotive industry, created by the German Association of the Automotive Industry (VDA) and the European Network Exchange (ENX). TISAX assessments, conducted by accredited auditors, evaluate organizations' information security management systems (ISMS) based on the VDA Information Security Assessment (ISA) catalog, aligned with ISO/IEC 27001. Results are shared on the TISAX platform, allowing automotive supply chain participants to verify compliance.
ISO/IEC 27001 ISMS Certification (ongoing)
ISO/IEC 27001 is a global standard for managing information security, detailing requirements for establishing, maintaining, and improving an Information Security Management System (ISMS). Certification involves implementing security measures, undergoing audits, and ensuring continuous improvement. The certification attests that companies comply with best practices to secure various types of information like financial information, intellectual property, employee details, or any other information entrusted from third parties.
General Data Protection Regulation (GDPR) Compliant
GDPR (General Data Protection Regulation) is an EU regulation protecting personal data and privacy of EU and EEA (European Economic Area) citizens. It sets strict rules for collecting, processing, storing, and transfering personal data and gives individuals more control over their data. Non-compliance can lead to hefty fines. At SPREAD, we comply fully with GDPR and regularly audit our processes to ensure ongoing compliance.
SPREAD leverages the latest software development techniques, giving you the flexibility to customize and adapt our platform to perfectly match your business needs.
SPREAD Cloud
This is the simplest, most common, and most cost-effective way to use SPREAD’s products.
Client Cloud
SPREAD also offers a managed deployment in your own cloud environment.
Custom & On-Premise
This is perfect if you are looking for a tailor-made solution that fits your operations.
SPREAD is TISAX certified (Scope ID: S1WZ1N) and efforts to be certified against ISO/IEC 27001:2022 are ongoing with a target certification timeline of Q3 2024.
How is the security of SPREAD products tested?
SPREAD features undergoes daily vulnerability scans performed by automated security tools to uncover potential flaws or misconfigurations. All findings are assessed and remediated according to our internal vulnerability management procedure. In addition to that, we have hired an external company specialized in Penetration Testing to conduct an assessment of our platform. Testing is performed annually or on a significant change in our architecture.
Does SPREAD have any rights to my data?
All data that you upload to or develop on the SPREAD platform remains owned by you and is treated as your confidential information.
Can we use multi-factor authentication for sign-in to SPREAD?
Multi-factor authentication (MFA) can be used when SSO is enabled, but is dependent on the features supported by your Identity Provider. MFA configurations are managed by your IdP Administrators.
How is SPREAD protected against cyber attacks?
SPREAD features undergoes daily vulnerability scans performed by automated security tools to uncover potential flaws or misconfigurations. All findings are assessed and remediated according to our internal vulnerability management procedure. In addition to that, we have hired an external company specialized in Penetration Testing to conduct an assessment of our platform. Testing is performed annually or on a significant change in our architecture.
How does SPREAD protect customer data?
All production data is physically resident within the EU and bound by the EU data protection laws. Additionally, the data at rest and in transit is encrypted using 256-bit AES encryption to ensure its integrity. We fulfill TISAX and are currently on the road to bing certified against the ISO/IEC27001:2002 standard
Which SPREAD deployment option is right for my business?
Most SPREAD customers are benefiting from the cost-effectiveness provided by SPREAD's SaaS deployment option ("SPREAD Cloud"). However, organizations with more stringent data governance policies or those required to comply with external standards and regulations might need the additional data isolation provided by Managed Deployments ("Client Cloud" or custom solution). Contact our Sales to help you with understanding the value of each deployment model.