Draft for internal review Confirm flagged items before publishing Remove this bar on publish

Security & Compliance

Security

Future 42 LLC operates ValSpark, hosted workforce software for automotive service shops. Shop data sits in that product, so the controls below are written down, monitored, and open to inspection.

Last reviewed  31 Aug 2026 Review cadence  Quarterly Owner  Security & Compliance

Where we stand

Current compliance posture, stated plainly

We would rather tell you exactly where we are than imply more than we have earned. FTR42 is mid-programme on SOC 2 Type II. No audit report exists yet, and we do not claim one.

SOC 2 Type II In progress Controls implemented and continuously monitored in Vanta. Observation window underway; independent audit not yet complete. No report is available at this time.
Trust Center Not live A public Trust Center at trust.valspark.ai is not a current customer channel. Do not treat it as an SLA or as live control status. This page and the Terms are the public record.
Written policies 11 approved Eleven Vanta policies are approved. Five remain in draft (Access Control, Code of Conduct, Human Resource Security, Physical Security, Incident Response) and are not claimed as approved here.
Continuous monitoring Vanta Infrastructure, identity and endpoint checks run automatically rather than at audit time only.

We hold no ISO 27001, HIPAA or PCI DSS attestation, and we do not represent ourselves as certified under any framework we have not completed.

01  /  Governance

Eleven approved policies, plus five still in draft

Approved policies are version-controlled in Vanta and renewed on an annual cycle. Draft policies are listed so we do not pretend they are done.

Asset Management Policy
Business Continuity & Disaster Recovery Plan
Cryptography Policy
Data Management Policy
Information Security Policy (AUP)
Information Security Roles and Responsibilities
Operations Security Policy
Privacy Compliance Policy
Risk Management Policy
Secure Development Policy
Third-Party Management Policy

Still draft: Access Control, Code of Conduct, Human Resource Security, Physical Security, Incident Response.

Risk management

We keep a risk register with inherent and residual scoring, and we run control self-assessments at least annually. Findings get an owner and a fix plan. We have no standing remediation SLA with customers unless a written SOW attaches one.

02  /  Data protection

Encryption, classification and retention

Data in transit

Confidential and sensitive data is encrypted with secure transport protocols whenever it crosses a public network. This applies to our own applications and to the interfaces we build for customers.

Data at rest

Customer data resides in managed cloud platforms, principally Supabase, AWS and Vercel, which encrypt at rest as a platform default. Privileged access to encryption keys is restricted to users with a documented business need.

Classification and retention

A data classification policy defines how information is categorised and handled, and documented retention procedures govern how long we keep it. We retain information for as long as needed to operate the service or to satisfy a legitimate business or legal requirement, and no longer.

Disposal

Electronic media holding confidential information is purged or destroyed in line with recognised practice, and a certificate of destruction is issued for each device destroyed.

03  /  Infrastructure

Production is separated, restricted and logged

  • Production application access is restricted to authorised users only.
  • Production databases (Supabase) restrict privileged access to people with a business need, using unique credentials and provider MFA where we have turned it on.
  • Hosting is serverless on Vercel and managed cloud services. We do not run our own servers, SSH bastions, or a company-owned network firewall.
  • Logs come from those providers and from application logs we retain for security and operations.
  • Inventory of in-scope assets is tracked in Vanta. Some integrations (Google Workspace, Supabase) still need to be reconnected so that inventory stays complete.

Physical data centres are operated by our cloud providers. We do not claim their building access as a control we perform ourselves.

04  /  Access control

Least privilege, enforced by tooling

Access is granted on the basis of role and business need, and removed when the need ends. Identity is centralised in Google Workspace; credentials that cannot be federated are held in a managed password manager rather than in documents or chat.

  • Passwords for in-scope systems are configured according to our password policy.
  • Privileged access to production consoles, databases, and encryption-key settings is separately restricted and individually justified.
  • Access is reviewed on a defined cycle, and revoked as part of offboarding.

05  /  Secure development

How code reaches production

We run a documented development lifecycle: GitHub for source, pull-request review on main, and Vercel for production deploys. Emergency changes still go through that path unless a documented exception is recorded.

  • Vulnerability handling is an engineering duty. We do not currently publish a pentest of production or sell an intrusion-detection product to customers.
  • Control self-assessments are performed at least annually, with an owner on findings.

06  /  Incident response

What happens when something goes wrong

The Incident Response Plan is still in draft in Vanta. Until it is approved, reports still go to security@ftr42.com. If we confirm an incident affecting customer materials on systems we operate, we notify the affected customer without unreasonable delay, as stated in the Terms.

A Business Continuity and Disaster Recovery plan is approved. It covers how we keep operating if key people are unavailable.

If you think you found a vulnerability in something we operate, write to the address below. We will acknowledge the report and keep you informed as we work it.

07  /  People

The smallest attack surface is a well-run team

FTR42 is a small, senior team, and our controls are built for that shape rather than borrowed from a larger one.

  • A Code of Conduct and Human Resource Security Policy exist as drafts in Vanta. Personnel will acknowledge them once they are approved. Until then, security expectations for each role sit in the approved Information Security Policy and Roles and Responsibilities policy.
  • Security responsibilities are assigned to named individuals, not left implicit.

08  /  Subprocessors

Who else touches the data

We assess third parties before we adopt them and review them on a recurring basis under our Third-Party Management Policy. The providers below support delivery of our services.

Current subprocessors and infrastructure providers
ProviderPurposeRisk tier
Amazon Web ServicesCloud infrastructure, Bedrock models, Titan embeddingsCritical
SupabaseApplication database and authenticationCritical
Google WorkspaceIdentity, email, documentsCritical
GitHubSource controlCritical
VercelApplication hostingHigh
AnthropicIn-app assistant and coaching textHigh
Apple / GoogleApp distribution, push, device speech-to-textHigh
StripeShop billing when the owner connects paymentHigh
BitwardenCredential managementHigh
VantaCompliance monitoring (not a ValSpark data processor for shop records)High
ResendFTR42 transactional email-
TwilioFTR42 marketing/lead SMS only; not ValSpark staff SMS-

Risk tiers reflect our internal inherent-risk assessment. Where a tier is not shown, the provider is in scope of our register but not yet tiered.

09  /  Contact

Reporting a vulnerability, or asking for more

Security reports: security@ftr42.com

Privacy and support: scale@ftr42.com (two business days, see valspark.ai/support)

Terms: ftr42.com/terms and valspark.ai/terms

Status: ftr42.com/status (public, no login)

Updates: ftr42.com/updates (public product change log)

Prospects, customers and auditors who need more than this page (control evidence, the policy set, a questionnaire, or an NDA first) should write to us. We will route it the same week.

This page is maintained by the Security & Compliance owner named at the top, reviewed quarterly, and re-confirmed whenever our practices, audits or policies change.