Trust and Security

Your customer data stays in your own shop system. We keep the service up, back everything up, and prove the backups work. This page explains all of it in plain words, written by a shop owner, not a legal team.

Your data

Your customer data stays yours

Sparviko reads from and writes to your own shop management system, live, while the caller is on the line. Your customer list lives where it always has: in your system, at your shop. We do not keep a standing copy of it on our servers, and we never will as a product offering.

Here is what we do keep, honestly. Call records for your own dashboard: who called, what happened, the recording, the summary. That is your call history, and it is there so you can check our work.

And here is the 30-day scrub. Once a call record is more than 30 days old, an automated job runs at night and blanks the personal details out of it: the name, the phone number, the recording, the transcript, the vehicle. The counts stay, so your dashboard numbers never lose history, but the personal information is gone. That is our standard for customer shops, and it runs on a schedule, not when somebody remembers.

The disks everything sits on are encrypted. If the hardware were ever pulled out of a rack and carried off, the data on it would be unreadable.

One more rule, and it is written down: one shop's data is never used for any other business's benefit. Your call history is not market research. It is yours.

Reliability

Built to stay up

If our system goes down, your phones ring with nobody home. We treat that as unacceptable, so we watch it three different ways, around the clock.

  • A 24/7 independent watchdog. A separate watchdog service runs on infrastructure completely independent from ours and checks our system around the clock, day and night. If we stop answering, it texts the founder, and it keeps texting until the problem is fixed.
  • Hourly self-checks. Every hour, our system runs a batch of automated security checks on itself. Is every door still locked, is every gate still closed. Any new failure sends a text to a human.
  • Weekly outside scans. Once a week, a scanner outside our network probes our servers the same way an attacker would, looking for known holes.
Backups

Backups that actually restore

We back up every day, encrypted, to storage away from our own servers. And once a month we prove those backups work by actually restoring one.

A backup you have never restored is a hope, not a backup. So on the first of every month, an automated test pulls real data back out of the offsite backup and verifies it came back intact. Not a checkbox that says the backup ran. An actual restore.

There are layers under that, too: full copies of the whole server every day, plus a separate nightly copy of the database. And the offsite backups are encrypted before they ever leave our server, so the storage company holding them cannot read them.

Access

Who can see your dashboard?

Only the people you put on the list. Your dashboard sits behind a sign-in gate, and that gate has one list per shop: the email addresses the owner approves. Nobody else gets in. Without a sign-in, the pages simply do not load. We have tested exactly that.

It works the way you would want it to. Add a new advisor's email once and they can see every page. Remove it once and they lose everything. No per-page permissions to fiddle with, no forgotten accounts hanging around.

And your shop is isolated. Each shop runs on its own instance of our system, never a shared platform with your data sitting in someone else's rows. Another shop's dashboard cannot reach your data, and yours cannot reach theirs.

Quality

Every call gets reviewed

A second AI reviews every call within the hour during business hours and flags anything off to a human. Not a sample. Every call. Machines are patient like that.

And nothing changes on your phone line untested. Every update to your assistant is tested against dozens of simulated callers before it touches a live line.

You are part of the loop too. Every call lands in your dashboard with a recording you can play, so you never have to take our word for how a call went. Go listen.

How we operate

Our rules for ourselves

Sparviko is run by the owner of an independent repair shop, and this system answers his own shop's phones every day. These rules exist because of that. It is your data and your shop. We behave like guests in your building.

  • Read-only first. Our default access to your system looks things up. It does not change anything.
  • You approve every write. Before our software gets the ability to write anything into your system, like booking an appointment, you approve that specific capability. Nothing gets write access by default.
  • Additive and reversible. Everything we set up runs alongside your system, not inside its guts. It can be removed cleanly. Nothing we do locks you in.
  • Nothing hidden. A technician from your software vendor remoting into your machine can see every tool we added. We do not bury anything.
  • A tight, locked-down connection. Where we connect to a shop database, the standard is a read-only account, scoped to that one database only, reachable only over a private encrypted tunnel.
  • Your setup logins are protected from day one. When you hand us a credential during onboarding, it is encrypted right in your browser before it is ever sent, and it is unlocked once, by the founder, to wire up your account. We also ask you to create a separate sign-in just for the AI, never your own personal login.
  • Proven at our shop before it reaches yours. Nothing unfinished ships to a paying shop. It runs at the founder's own shop first.
The honest part

No SOC 2 yet. Here is what we do instead.

We do not have a SOC 2 report or an outside security certification yet. We are a young company, and an audit like that costs more than makes sense at our size today. We plan to get there as we grow, and we would rather tell you that straight than dress this page up to look like something it is not.

In the meantime, here is what we actually run:

  • Written policies for how we run security, what we do if something goes wrong, and how long we keep data. Not paperwork on a shelf. They are how we operate.
  • Two-step sign-in on our own accounts, on every account that supports it.
  • Encrypted disks, encrypted offsite backups, and a monthly restore test that proves the backups are real.
  • Hourly self-checks, weekly outside scans, and a 24/7 watchdog on independent infrastructure.
  • The 30-day scrub of personal details from call records, automated, every night.
Two standing commitments, in plain terms.
Personal details in call records are scrubbed after 30 days. Automatically, not on request.
And if something ever goes wrong involving your data, we tell you within 72 hours of learning about it. No sitting on it, no waiting for the news to break.

Last updated: September 2026