Does Spur perform penetration testing and vulnerability scanning?
Yes. Spur performs penetration testing at least annually, with a remediation plan tracked to completion, and runs host-based vulnerability scans at least quarterly on all external-facing systems, with critical and high findings tracked to remediation. See trust.spur.us for the full list of published security controls.
Similar questions
Does Spur provide security and compliance documentation?
Yes. Security, compliance, and vendor-review documentation is available self-serve at trust.spur.us, Spur's Trust Center. Compliance questions specific to your organization that aren't covered there can go to your account team or support@spur.us.
Does Spur have an incident response plan and a business continuity/disaster recovery plan?
Yes. Spur maintains documented security and privacy incident response policies, with the incident response plan tested at least annually, and a Business Continuity/Disaster Recovery plan that is also tested at least annually. See trust.spur.us for the full list of published security controls.
Does Spur perform background checks and require security training for employees?
Yes. Spur performs background checks on new employees, and requires all employees to complete security awareness training within 30 days of hire and at least annually thereafter. See trust.spur.us for the full list of published security controls.
Is data encrypted in transit?
Yes. Spur uses secure data transmission protocols to encrypt confidential and sensitive data whenever it's transmitted over public networks. See trust.spur.us for the full list of published security controls.
Where is Spur's infrastructure hosted, and who are your subprocessors?
Spur's cloud hosting platform runs on Google Cloud Platform (US-East). The current list of subprocessors is published and kept up to date at trust.spur.us.
Related guides & explainers
Switching Between Organizations
If your account belongs to more than one Spur organization, use the Organization Switcher to move between them and manage each organization's plan and settings separately.
What "Client Proxies" Means in Spur Data
"Client Proxies" in Spur data describes proxy-network activity Spur observed coming from an IP — it does not mean the IP is owned or operated by the listed provider.
How Spur IP Classifications Work: Observed Behavior, Not IP Ownership
Spur classifications describe what was observed happening on an IP during a given window, not who owns the IP or ASN — a key distinction when investigating a classification that looks wrong.
Why Residential Proxy Classifications Can Appear on Legitimate Infrastructure
Residential proxy networks recruit real consumer devices to relay traffic, so a legitimate ISP's own IP ranges can show a residential-proxy classification without the ISP's knowledge or involvement.