Security
Last updated: August 16, 2026
Our Approach to Security
Aspyr Insights Inc. is headquartered in Los Angeles, California, and builds Cockpit to handle sensitive contract, spend, and vendor data responsibly. Security is built into how we design, build, and operate the platform — not treated as an afterthought.
Data Encryption
Data is encrypted in transit using industry-standard TLS, and encrypted at rest using industry-standard encryption algorithms.
Access Controls
We apply the principle of least privilege to internal access to customer data, use role-based access controls, and require multi-factor authentication for access to critical systems.
Infrastructure
Cockpit is built on reputable cloud infrastructure providers that maintain their own independent security and compliance programs. We monitor our infrastructure for availability and irregular activity on an ongoing basis.
Monitoring and Incident Response
We maintain logging and monitoring across our systems to help detect and respond to potential security events, and maintain an internal process for triaging and responding to incidents.
Vendor and Subprocessor Management
Where we rely on third-party service providers to help deliver the Service, we review their security practices and require appropriate data protection commitments before sharing customer data with them.
Responsible Disclosure
If you believe you have discovered a security vulnerability in Cockpit or the aspyrinsights.com website, please report it to security@aspyrinsights.com. Please include enough detail for us to reproduce the issue, and give us a reasonable opportunity to investigate and address it before disclosing it publicly. We do not pursue legal action against good-faith security research conducted under this policy.
Your Role in Security
Security is a shared responsibility. We encourage customers to use strong, unique credentials, enable available account protections, and promptly notify us of any suspected unauthorized access at security@aspyrinsights.com.
Contact Us
Questions about our security practices can be directed to security@aspyrinsights.com or Aspyr Insights Inc., Los Angeles, California.