How Spaceboy protects customer data: the practices, infrastructure, and subprocessors behind the Service. Read together with the Privacy Policy and, for organizations that accept it, the Data Processing Addendum.
1. Infrastructure
Spaceboy runs on Google Cloud Platform. Customer projects deploy to isolated environments; remote development workspaces are ephemeral and torn down when sessions end. Production systems are managed as code, and access to production infrastructure is restricted to a small set of engineers using hardware-backed multi-factor authentication.
2. Data Encryption
All data is encrypted in transit using TLS 1.2 or higher and at rest using AES-256 (the default at-rest encryption of Google Cloud services). Secrets and integration tokens are stored encrypted and are never exposed in logs or client responses.
3. Authentication and Access
Platform sign-in supports email, social providers, and — for Enterprise organizations — SAML 2.0 single sign-on with optional enforced SSO for members on verified domains. Organization roles (owner, admin, member) gate management surfaces; audit-relevant actions are recorded in an append-only audit log that Enterprise organizations can export.
4. Tenant Isolation
Customer code, chat history, and application data are scoped to the owning organization at the data layer. Agent workspaces run in per-session isolated environments with no network path to other tenants' workspaces.
5. AI and Model Providers
Coding agents run on foundation models operated by the model vendors listed below. Spaceboy does not use customer code or prompts to train its own models, and its model-vendor agreements prohibit training on customer data. Enterprise organizations can restrict which models their members may use.
6. Availability and Continuity
Databases are backed up continuously with point-in-time recovery. Deployed customer applications and the platform itself run on redundant, autoscaling infrastructure.
7. Vulnerability Management and Incident Response
Dependencies are monitored for known vulnerabilities and patched on a regular cadence. Security incidents follow a documented response process; customers affected by a personal data breach are notified without undue delay, as described in the DPA.
8. Subprocessors
Spaceboy engages the following subprocessors to provide the Service:
- Google Cloud Platform (USA) — cloud infrastructure, storage, and databases;
- Supabase (USA) — platform and application authentication, managed Postgres for deployed applications;
- Stripe (USA) — payment processing and billing;
- Anthropic (USA) — foundation model provider for coding agents;
- OpenAI (USA) — foundation model provider for coding agents;
- Cursor (Anysphere, USA) — agent runtime for code generation;
- Slack (USA) — messaging integration, where the customer connects it;
- GitHub (USA) — repository hosting integration, where the customer connects it.
This list is updated before a subprocessor is added or replaced; the "Last updated" date above reflects the latest change.
9. Data Residency and Retention
Customer data is stored in the United States. Chat, run, and audit history are retained in full for the life of the account; organizations can export them at any time, and account deletion removes customer data in accordance with the Privacy Policy.
10. Reporting a Vulnerability
Report suspected vulnerabilities to security@spaceboy.ai. We acknowledge reports promptly and keep reporters informed through remediation.
11. Contact
Spaceboy, Inc.
272 Citrus Drive, Summerville SC 29486
Security: security@spaceboy.ai
Legal: legal@spaceboy.ai