אילו תקנים אנו עומדים בהם, מה בתהליך ומה לא טוענים
Spun נבנה עם פרטיות ואבטחה מהיסוד. אנו משתמשים בהצפנה בהעברה, גישה מבוקרת, רישום ביקורת, שמירת נתונים ניתנת להגדרה ותכונות AI בשליטת הלקוח. אנחנו לא מגזימים — כל סטטוס להלן עדכני.
סטטוס לפי תקן
איפה אנחנו עומדים
כל תקן להלן מוצג עם סטטוס נוכחי. אם סטטוס "בתהליך" או "במפת הדרך", שאל אותנו לגבי אבן הדרך האחרון.
SOC 2
מה זה
AICPA framework covering security, availability, confidentiality, processing integrity, and privacy controls for service organizations. Type I is point-in-time; Type II is over a 6–12 month period.
העמדה שלנו
SOC 2 readiness program in progress: access logging, change-management, vendor review, vulnerability scanning, incident response, employee access policy, and least-privilege controls are all in place. Type I attestation targeted for the second half of 2026; Type II to follow once we have operational history.
GDPR (EU/EEA)
מה זה
EU regulation governing personal data of EU/EEA residents. Spun typically acts as a data processor; the customer is the controller of their end-user data.
העמדה שלנו
GDPR-aligned controls in place: lawful basis documentation, DPA available on request (with EU Standard Contractual Clauses for international transfers), published sub-processor list, data minimization defaults, retention controls, customer-controlled export and deletion, AI processing disclosure, and breach-notification procedure within the 72-hour requirement.
ISO/IEC 27001
מה זה
International standard for information security management systems (ISMS). Widely recognized for enterprise / international procurement.
העמדה שלנו
On the roadmap after SOC 2 Type II. Many of the underlying controls overlap with our SOC 2 readiness work, so the incremental effort is significant but not green-field.
EU AI Act
מה זה
EU regulation in force since 1 August 2024, with most rules applying from 2 August 2026. Risk-tiered obligations: prohibited / high-risk / limited-risk / minimal-risk AI systems.
העמדה שלנו
Spun's AI features (compose, summarize, transcribe, translate, smart replies, classification) are limited-risk by default — used for general business communication, not high-stakes decisions about people. We provide AI-usage disclosure, customer toggles per feature, audit logging (optional), human-approval modes, no training on customer data, vendor disclosure, and PII redaction before AI processing. If you are using Spun in a use case that becomes high-risk under the Act (hiring decisions, credit, health, education, legal advice, biometric ID), contact us.
Israeli Privacy Protection Law (Amendment 13)
מה זה
Israel's privacy law modernized in 2024 (effective August 2025), bringing it closer to GDPR-style obligations.
העמדה שלנו
Spun's GDPR-aligned controls cover most of the core obligations under the updated Israeli law. Database registration: Spun stores customer contact data only to provide the SaaS workspace to each customer — we do not sell, broker, transfer, or independently use customer contact lists. Contact data remains logically separated by organization (RLS-enforced). Spun is not a public body. Under Amendment 13, registration mainly applies to public-body databases and data-broker/direct-mailing databases exceeding 10,000 records; our processor-only model does not trigger registration at launch. We will reassess if Spun offers large-scale direct-mailing/broadcast services, combines contact lists across customers, or transfers contact data beyond listed sub-processors. Hebrew-language privacy materials and DPO designation (if required at scale) are in progress.
שמירת נתונים
מגבלות שמירה לפי תוכנית
הודעות ישנות נמחקות אוטומטית בהגעת מגבלת התוכנית. ניתן להחמיר שמירה לכל צ׳אט ב-בטיחות ופרטיות → מגבלת אחסון הודעות, או למחוק הכל לפי דרישה.
| תוכנית | היסטוריית הודעות | אחסון מדיה |
|---|---|---|
| Free Trialתקופת ניסיון 7 ימים | 30 days | 5 GB |
| Basic | 90 days | 10 GB |
| Pro | 1 year | 75 GB |
| Power | Unlimited | 500 GB |
במחיקת חשבון, כל המידע האישי מוסר או מואנונים תוך 30 יום, למעט במקרים ששמירה נדרשת על פי חוק (רשומות פיננסיות, מניעת הונאה).
איפה הנתונים שלך נמצאים
אירוח אזורי
כל שרתי האפליקציה ובסיס הנתונים נמצאים במרכז נתונים EU יחיד. אתר השיווק וקבצי המדיה מוגשים גלובלית מרשת הקצה של Cloudflare להשהיה נמוכה בכל מקום.
Hetzner Nuremberg
EU (Germany) — application servers + PostgreSQL
The single data tier. All application servers, database, and Redis run here. AES-256 encrypted disks.
Cloudflare Pages
Global edge — marketing site & static assets
spun.com and 20+ regional domains served from Cloudflare's global edge network. Visitors get the nearest PoP automatically.
Cloudflare R2
Global — images, video, file attachments
All media (images, video, audio, documents) stored in R2 with AES-256 at rest. Access gated by per-org, per-object signed URLs.
Israel region
Israel
Under evaluation for Israeli market expansion. Currently Israeli customers are served from Hetzner Nuremberg (EU).
India region
India
Under evaluation for Indian-language voice features and data residency.
איפה אנחנו מוכרים, ולמה
מפת דרך השקה בינלאומית
אנו משיקים בשווקים שבהם WhatsApp הוא תשתית עסקית מרכזית תחילה, ומתרחבים לשווקי ארגון עם דרישות תאימות גבוהות יותר כשההסמכות שלנו מתבגרות.
- 1
ישראל ואמריקה הלטינית (נוכחי)
ישראל (ממשק עברית + אנגלית, מתואם GDPR). מקסיקו, קולומביה, ארגנטינה, צ׳ילה, פרו, איחוד האמירויות — WhatsApp הוא תשתית עסקית אוניברסלית, מחזורי מכירה קצרים. מוכנות SOC 2 מספיקה.
- 2
עסקים קטנים-בינוניים בארה"ב (נוכחי, מתרחב)
שירותי בית, נדל"ן, תמיכת מסחר אלקטרוני, תיירות, חינוך, בריאות. SOC 2 Type I וחבילת DPA מלאה הופכים את Spun לישים לרוב קוני SMB ושוק ביניים בארה"ב.
- 3
ארגוני EU ובריטניה (אחרי SOC 2 Type I)
כניסה לאחר חתימת SOC 2 Type I ותחילת עבודה על ISO 27001. דורש DPA + SCCs מלוטשים, אישור אירוח EU וכלי מחיקה/ייצוא מלאים — הכל קיים אך נהנה מאישור צד שלישי לפני מכירות ארגוניות גדולות יותר.
מסמכים זמינים
בקשה מ[email protected]
הסכם עיבוד נתונים (DPA)
מתואם GDPR, כולל סעיפי חוזה סטנדרטיים של EU להעברות בינלאומיות.
רשימת עדכוני ספקי משנה
קבל עדכוני אימייל כשאנו מוסיפים או משנים ספק משנה.
סקירת אבטחה
ארכיטקטורה, הצפנה, בקרת גישה, ניהול פגיעויות.
מדיניות עיבוד נתוני AI
אילו ספקי AI, מה הם רואים, התחייבות לאי-אימון.
מדיניות תגובה לאירועים
זיהוי, הכלה, לוחות זמנים להתראת לקוחות.
מדיניות שימוש מקובל
מה מותר ב-Spun והבסיס לאכיפה.
יש לך שאלון אבטחה?
אנו משיבים לשאלוני אבטחה סטנדרטיים (SIG, CAIQ, ארגוני מותאם אישית) תוך 5 ימי עסקים. שלח אימייל ל- [email protected] עם לוח הזמנים שלך.