Security · Compliance
Designed for the frameworks enterprises expect.
Spark ERP is built with these compliance frameworks in mind. None of the certifications below have been obtained yet — this page will be updated the moment any of them are, with evidence, not before.
How to read this page
Every framework below is labeled "Designed for" because Spark ERP has not completed a formal certification or audit against it. We do not display certification badges or claim compliance we have not independently verified. If a framework is later certified, this page will say so explicitly and link the certificate.
SOC 2
Designed forAccess control, change management, availability and audit logging in the platform reflect SOC 2 Trust Services principles. A formal SOC 2 audit has not been completed.
ISO 27001
Designed forInformation security practices — access control, encryption, incident handling — are built with ISO 27001's control areas in mind. No ISO 27001 certification has been obtained.
GDPR
Designed forTenant data isolation, encryption, and regional deployment support GDPR-relevant requirements such as data residency and the ability to isolate and export a tenant's data. This is not a legal determination of GDPR compliance for your specific use.
DPDP
Designed forThe same tenant isolation, residency and access-control foundations that support GDPR are built with India's Digital Personal Data Protection Act in mind.
HIPAA
Designed forEncryption, access control and audit logging align with HIPAA safeguards, but Spark ERP has not undergone a HIPAA compliance assessment and is not represented as a Business Associate today.
PCI DSS
Designed forSpark ERP is not certified against PCI DSS. Where payment data is involved, we recommend routing card data through a certified payment processor rather than storing it directly.
Need a specific compliance framework?
Tell us which frameworks matter for your organization and we'll walk through exactly what the platform does and does not currently cover.