Security & Trust

Last updated: July 29, 2026

AeroSpark reads your contracts. That is the whole product, so it is reasonable to ask exactly what happens to a document after you upload it, who can see it, and what our AI provider is permitted to do with it. This page answers those questions directly.

1. Where your data lives

If you connect Google Drive or Microsoft SharePoint, approved documents are also written to your storage, in the folder you nominate. That copy is governed by your own tenant's policies, not ours.

2. Encryption

The document bucket blocks all public access — public ACLs, public bucket policies, and public listing are all disabled.

3. AI and your documents

This is the question we get asked first, so it gets a direct answer.

4. Isolation between customers

Every record — request, contract, policy, audit entry — is scoped to a tenant identifier, and every query is filtered by it. Reviewer and administrator actions in Microsoft Teams re-derive the tenant from a trusted server-side lookup rather than trusting the identifier supplied by the client, because interactive card payloads are client-controllable and can be spoofed. That rule is enforced in code review and covered by automated tests.

5. Access control

6. Document retention

Documents you submit are retained in your workspace for as long as your account is active, so that your contract register, version history and audit trail stay complete — a register with gaps in it is not much use during a renewal or a dispute.

To have specific documents or an entire workspace deleted, contact [email protected] and we will action it.

7. Subprocessors

These third parties may process customer content on our behalf:

These are used only where you enable the corresponding integration:

8. How we work

9. Reporting a vulnerability

If you believe you have found a security issue, email [email protected]. Please include enough detail to reproduce it. We will acknowledge your report and keep you updated while we investigate, and we will not pursue action against good-faith research that avoids privacy violations, data destruction, and service disruption.

10. Contact

AeroSpark.ai Inc.
Security: [email protected]
Legal and privacy: [email protected]

See also our Privacy Policy and Terms of Service.

Common questions

Who inside our company can see our contracts?

Only the people you give the Legal or Admin role. The contract register is restricted to those roles; everyone else sees the requests they submitted themselves.

What happens to our documents if we stop using AeroSpark?

They are retained in your workspace for as long as your account exists. To have specific documents or an entire workspace deleted, contact us — deletion is handled on request rather than self-service today.