Security at SPRINGS-C
Protecting the SPRINGS-C platform and Customer Data
SPRINGS-C LLC ("SPRINGS-C," "we," "us," or "our") develops and operates the SPRINGS-C CRM and operations platform for cleaning companies.
Security is part of how the SPRINGS-C platform is designed, operated, maintained, and supported.
Our security approach combines access controls, organization-level authorization, transport security, environment separation, monitoring, logging, controlled software changes, backup and recovery processes, incident management, and Customer security responsibilities.
The controls applicable to a particular Customer may depend on the Services, configuration, infrastructure, integrations, and applicable commercial agreement.
No internet-connected system can eliminate all security risk. This page describes SPRINGS-C's current security approach and should not be interpreted as a guarantee that unauthorized access, service interruption, data loss, or another security incident can never occur.
- Last updated
- August 12, 2026
- Applies to
- springs-c.com
- Provided by
- SPRINGS-C LLC
This page is a public security overview. It is not a certification, an audit report, a penetration-test report, a service-level agreement, or a guarantee that security incidents cannot occur.
Security Overview
1. Security Responsibilities
Security of a business software platform is a shared responsibility.
SPRINGS-C is responsible for operating and protecting the parts of the platform and infrastructure that SPRINGS-C controls.
Customers are responsible for security decisions within their own organization, including:
- selecting appropriate Authorized Users;
- assigning appropriate roles and permissions;
- protecting credentials;
- removing access when personnel no longer require it;
- securing Customer-controlled devices;
- securing exported data;
- securing Customer-managed integrations;
- determining what information is appropriate to enter into the platform;
- protecting credentials or API access provided to third-party integrations;
- maintaining security for systems outside SPRINGS-C's control.
SPRINGS-C provides platform-level controls, but Customer configuration and account-management decisions remain important parts of the overall security model.
Identity and Access
2. Access Control
SPRINGS-C uses access controls designed to restrict access to information and functionality according to authorization.
Access decisions may take into account:
- Customer organization;
- Authorized User;
- role;
- assigned permissions;
- requested action;
- relevant product context.
Users should only receive access appropriate to the responsibilities assigned to them by the Customer.
3. Role-Based Access Control
SPRINGS-C uses role-based access control to help Customers limit access to functionality and information according to operational responsibilities.
Depending on product configuration, Customers may assign different permissions to administrators, managers, operational personnel, cleaners, or other Authorized Users.
Customers are responsible for assigning roles appropriate to their organization and periodically reviewing access as personnel and responsibilities change.
4. Least Privilege
SPRINGS-C applies least-privilege principles to access under its control.
Access should be limited to the information, systems, and capabilities reasonably necessary for the relevant role or operational task.
Elevated or administrative access should not be used for routine activities where lower levels of access are sufficient.
SPRINGS-C also encourages Customers to apply the same principle when assigning permissions to their own users.
5. Organization-Level Data Access
SPRINGS-C uses organization-level authorization controls designed to restrict users to Customer data and functionality that they are authorized to access.
Application requests are evaluated in the context of the authenticated user, Customer organization, assigned permissions, and requested operation.
These controls are intended to reduce the risk of unauthorized access between Customer organizations.
6. Authentication
SPRINGS-C requires authentication for access to protected Customer functionality.
Authentication and session controls are used to help verify users and restrict unauthorized access to authenticated areas of the platform.
Customers are responsible for protecting user credentials and ensuring that accounts are assigned to appropriate individuals.
Customers should notify SPRINGS-C if they suspect that credentials or an account have been compromised.
Data Protection
7. Data in Transit
SPRINGS-C uses TLS-based transport security for supported communications between users and production SPRINGS-C services.
Transport security helps protect information against unauthorized interception while it is transmitted over supported network connections.
SPRINGS-C also expects integrations and service-to-service connections to use appropriate protected transport mechanisms where supported.
8. Stored Information
Production databases, file storage, backups, and other stored information are protected using the security controls available in the configured infrastructure and service environment.
Access to stored Customer information is subject to applicable access, authorization, infrastructure, and operational controls.
9. Secrets and Credentials
Sensitive system credentials and service secrets should be handled separately from ordinary application content and should not be intentionally exposed through public website code or Customer-facing interfaces.
SPRINGS-C applies access restrictions to operational credentials according to the needs of the relevant systems and personnel.
Customers should not submit passwords, full payment-card credentials, private API secrets, or other unnecessary authentication information through ordinary Contact, Demo, or Solution Quiz forms.
Application Security
10. Environment Separation
SPRINGS-C separates development and production environments as part of its software-development and operational practices.
Production access and production changes are treated differently from ordinary development activity.
Environment separation is intended to reduce unnecessary exposure of production systems and Customer information during development and testing activities.
Customer production data should not be copied into development environments merely for convenience.
11. Change Management
SPRINGS-C uses controlled change-management practices for production software and infrastructure changes.
Changes may involve:
- implementation;
- review;
- testing;
- deployment;
- monitoring;
- corrective action where necessary.
The exact process depends on the nature and risk of the change.
Material production changes should be introduced through controlled deployment processes rather than uncontrolled direct modification.
12. Secure Development
Security considerations are incorporated into development and maintenance of SPRINGS-C.
Relevant practices may include:
- input validation;
- authorization checks;
- dependency management;
- separation of environments;
- controlled production changes;
- error handling;
- security review of sensitive functionality;
- monitoring of production behavior;
- remediation of identified security issues.
The exact security activities depend on the nature and risk of the relevant code or change.
13. Input Validation and Application Controls
SPRINGS-C uses input-validation and application-level controls intended to reduce the risk of malformed, unexpected, or unauthorized input affecting the Services.
Authorization checks are applied separately from ordinary input validation where access to protected information or actions is involved.
No validation mechanism is treated as a substitute for other layers of application and infrastructure security.
Monitoring and Logging
14. Monitoring
SPRINGS-C monitors production service availability and application errors to support operational reliability and security investigation.
Monitoring may help identify:
- service failures;
- unexpected errors;
- availability issues;
- operational anomalies;
- security-relevant events.
Monitoring is used as one source of operational and security information.
15. Logging
SPRINGS-C records selected authentication, administrative, security, and operational activities to support accountability, troubleshooting, security investigation, and service operation.
Logging may include information such as:
- authentication events;
- administrative actions;
- system events;
- errors;
- security-relevant events;
- operational activity required to support the Services.
Not every user action or every field-level change is necessarily recorded.
Logging scope and retention may depend on the system, event type, infrastructure, and applicable Customer agreement.
Availability and Recovery
16. Availability and Reliability
SPRINGS-C uses operational monitoring and infrastructure processes intended to support availability and reliable service delivery.
Like other internet-based services, SPRINGS-C may experience interruptions caused by maintenance, software defects, infrastructure failures, third-party service failures, internet conditions, security events, or circumstances outside reasonable control.
Any contractual uptime commitment applies only where it is expressly included in the applicable Customer agreement.
17. Backups and Recovery
SPRINGS-C maintains backup and recovery processes appropriate to the configured production infrastructure and applicable service arrangements.
Backup and recovery processes are intended to support restoration following certain failures, operational errors, or other events affecting production information.
The exact backup scope, frequency, retention, storage architecture, and recovery process depend on the configured infrastructure and applicable Customer agreement.
18. Data Export and Account Closure
SPRINGS-C provides Customer data access, export, and deletion paths according to available product functionality and applicable contractual arrangements.
Customers are encouraged to export information they reasonably require before account closure where applicable functionality is available.
Data retention and deletion after termination are governed by the applicable commercial agreement, Data Processing Agreement where applicable, Privacy Policy, technical backup lifecycle, and applicable law.
Incident Management
19. Incident Management
SPRINGS-C maintains processes for identifying, investigating, containing, and responding to security incidents affecting systems under its control.
Incident response may include activities such as:
- assessment;
- containment;
- remediation;
- recovery;
- investigation;
- preservation of relevant information;
- communication where appropriate.
The actions taken depend on the nature, scope, impact, and available information relating to the incident.
20. Security Incident Notification
Where SPRINGS-C becomes aware of a security incident or personal data breach that creates an applicable Customer notification obligation, SPRINGS-C will handle notification according to applicable law and the relevant Customer agreement or Data Processing Agreement.
Initial information may be incomplete while an incident is being investigated. Where appropriate and required, SPRINGS-C may provide additional material information as it becomes reasonably available.
21. Vulnerability Management
SPRINGS-C evaluates identified security issues affecting systems and software under its control and prioritizes remediation according to factors such as potential impact, exploitability, exposure, and operational risk.
Remediation methods may include:
- software updates;
- configuration changes;
- dependency updates;
- access restrictions;
- infrastructure changes;
- temporary mitigations;
- other appropriate corrective measures.
22. Security Testing
SPRINGS-C may perform security review and testing appropriate to the nature and risk of relevant systems and software changes.
The scope and method of testing may vary depending on the component, change, infrastructure, and risk being evaluated.
This public page does not claim a specific penetration-testing frequency or independent audit schedule.
Third-Party and Payment Security
23. Dependency and Third-Party Risk
SPRINGS-C relies on third-party infrastructure and service providers for portions of its technology environment.
Security of the SPRINGS-C Services therefore includes consideration of provider capabilities, contractual arrangements, technical integrations, access requirements, and other relevant risks.
Different providers may be responsible for different portions of the underlying technical environment.
SPRINGS-C does not represent that use of a third-party provider transfers all security responsibility to that provider.
24. Payment Security
Payments for SPRINGS-C Services may be processed through third-party payment service providers and financial institutions.
Depending on the payment integration, payment credentials may be collected or processed using payment technology supplied by the relevant payment service provider.
SPRINGS-C may receive transaction identifiers, payment status, payment-method information, billing information, refund information, fraud signals, or other payment-related information necessary to administer the Customer relationship.
The exact payment-data flow depends on the payment method and configured payment integration.
Customers should not send full payment-card numbers, card security codes, or other unnecessary payment credentials to SPRINGS-C through ordinary email, Contact, Demo, or Solution Quiz forms.
25. Fraud and Abuse Prevention
SPRINGS-C may use account, technical, transaction, security, and payment-related information where reasonably necessary to prevent or investigate fraud, abuse, unauthorized access, account compromise, or other misuse of the Services.
Payment service providers may independently apply additional authentication, fraud-prevention, and risk controls according to their own legal and technical requirements.
Security or fraud controls should not be used merely to make legitimate Customer cancellation or refund requests unnecessarily difficult.
AI Security
26. AI Security and Permissions
SPRINGS-C may provide AI-assisted functionality that operates using information available within the permissions and context of an Authorized User.
AI-assisted functionality is intended to respect applicable product permissions rather than provide unrestricted access to Customer information.
Where selected AI-assisted functionality can initiate or prepare a critical operation, SPRINGS-C may require user confirmation before the operation is completed.
AI-generated output should be reviewed before it is relied upon for material business decisions.
27. AI Data Handling
Information processed through AI-assisted functionality may be handled by configured AI services according to the applicable feature, provider, Customer agreement, product configuration, and provider terms.
SPRINGS-C does not state on this page that every configured AI provider:
- never retains Customer information;
- never uses information for service improvement;
- never uses information for model training;
- processes information only in one jurisdiction.
Where an AI provider processes Customer Personal Data on behalf of SPRINGS-C, the relationship is addressed according to applicable contractual, privacy, and subprocessor requirements.
Customer Responsibilities
28. Customer-Authorized Integrations
Customers may connect SPRINGS-C to third-party services.
Security of an integration depends partly on the third-party service, credentials, permissions, configuration, and Customer decisions involved.
Customers are responsible for:
- authorizing appropriate integrations;
- limiting permissions where supported;
- protecting integration credentials;
- disabling integrations that are no longer required;
- evaluating the security and privacy practices of third-party services they choose.
SPRINGS-C is responsible for the security of the SPRINGS-C-controlled portion of an integration, but does not control the independent systems of a third-party provider.
29. Employee and Operational Access
SPRINGS-C applies access restrictions to internal or operational access under its control according to role and business need.
Access to production information should be limited to authorized purposes such as:
- operating the Services;
- support;
- security investigation;
- maintenance;
- resolving technical issues;
- performing authorized Customer requests;
- complying with lawful obligations.
SPRINGS-C personnel should not access Customer information merely because technical access may be possible.
30. Confidentiality
Individuals authorized by SPRINGS-C to access non-public Customer information are expected to be subject to appropriate confidentiality responsibilities or equivalent obligations.
Confidential information should be used only for legitimate business, operational, support, security, or legal purposes.
Additional confidentiality obligations may apply through Customer agreements.
31. Customer Security Responsibilities
Customers have an important role in protecting their SPRINGS-C environment.
Customers should:
- use individual user accounts;
- protect account credentials;
- avoid credential sharing;
- assign the minimum permissions reasonably required;
- review administrative access;
- remove users who no longer require access;
- secure devices used to access SPRINGS-C;
- protect exported information;
- use secure integrations;
- review suspicious account activity;
- notify SPRINGS-C of suspected unauthorized access;
- apply appropriate human review to sensitive AI-assisted actions.
SPRINGS-C cannot protect Customer systems, devices, credentials, or third-party services that are outside SPRINGS-C's control.
32. Security and Privacy of Customer Data
Customer Data remains subject to the contractual, privacy, security, and data-processing terms applicable to the Customer's use of SPRINGS-C.
SPRINGS-C does not acquire ownership of Customer Data merely because it is processed through the Services.
Information about controller and processor roles, subprocessors, international processing, privacy rights, retention, export, and deletion is available in the Data Processing Information and Privacy Policy.
33. Security of Data After Export
Security protections provided inside the SPRINGS-C platform may no longer apply after information is exported, downloaded, copied, transferred, or otherwise moved into Customer-controlled or third-party systems.
Customers are responsible for protecting exported information according to their own security and privacy obligations.
Compliance Status
34. Security and Compliance Status
SPRINGS-C maintains security practices appropriate to its current Services and operating environment.
SPRINGS-C does not currently claim SOC 2 certification.
SPRINGS-C does not currently claim ISO 27001 certification.
SPRINGS-C does not claim PCI DSS certification through this page.
SPRINGS-C does not represent that the platform is automatically compliant with every law or regulatory framework applicable to every Customer.
Compliance requirements may depend on the Customer's industry, location, data, workflows, configuration, and contractual requirements.
Where a Customer requires a specific regulatory or certification framework, the requirement should be reviewed during procurement before regulated data is introduced into the Services.
35. HIPAA-Regulated Information
Organizations that require HIPAA-regulated processing must complete a separate legal, technical, and contractual review before using SPRINGS-C for protected health information.
The availability of ordinary security functionality does not itself establish that a particular Customer use case satisfies HIPAA requirements.
36. Payment Card Compliance
Payment-card security obligations depend on the payment architecture and responsibilities of SPRINGS-C, the Customer, and the relevant payment service provider.
SPRINGS-C does not use this page to claim PCI DSS certification.
Where payment-card functionality is used, the applicable payment architecture and compliance responsibilities should be evaluated according to the actual integration and relevant payment-provider requirements.
Security Reporting
37. Security Reviews and Due Diligence
Customers, enterprise procurement teams, payment service providers, and other authorized parties may request reasonable information about SPRINGS-C security practices as part of a legitimate due-diligence process.
Certain security information may not be appropriate for unrestricted public disclosure.
Depending on the nature of the request, additional information may be provided subject to appropriate confidentiality, verification, contractual, or security restrictions.
Requests may be sent to [email protected].
38. Report a Security Concern
If you believe you have identified a security issue affecting SPRINGS-C, please report it responsibly to [email protected].
Please include enough information for SPRINGS-C to understand and investigate the issue.
Do not include unnecessary Customer Personal Data, full payment-card credentials, passwords, or unrelated confidential information in the initial report.
Security research must not involve unauthorized access, destruction, disruption, social engineering, data exfiltration, or access to another Customer's information.
SPRINGS-C does not publish a monetary bug-bounty commitment through this page.
39. Security Incidents Affecting Customers
If an incident affecting Customer information creates an applicable notification obligation, SPRINGS-C will communicate according to the relevant contractual and legal requirements.
SPRINGS-C may use the Customer's designated administrative or security contacts for such communications.
Customers are responsible for maintaining current contact information for individuals who should receive important account and security communications.
40. No Absolute Security Guarantee
Security is an ongoing risk-management process.
SPRINGS-C works to protect its Services and Customer Data using controls appropriate to the current platform and operating environment, but no software, network, infrastructure provider, authentication method, encryption mechanism, monitoring system, or security process can guarantee that all security incidents will be prevented.
Customers should evaluate SPRINGS-C in the context of their own security, legal, contractual, and regulatory requirements.
Contact
41. Security Contact
Questions about SPRINGS-C security practices or legitimate security due-diligence requests may be directed to:
SPRINGS-C LLC, Entity ID 0008102431, 1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110, United States.
Last updated: August 12, 2026