Recovery records hold some of the most personal details of a person’s life. Protecting that trust shapes how we design SparkDNA, choose our infrastructure and control access to information.
This page describes the SparkDNA Horizons security architecture. Hosting arrangements, operational safeguards and your organisation’s requirements are reviewed as part of onboarding.
Defence in depth
Protection is built across independent layers. Network restrictions, verified connections, application permissions and encryption work together to limit exposure if one control fails.
Cloudflare edge
HTTPS connections reach Cloudflare before the AWS origin, providing the edge layer for traffic protection.
Verified AWS origin
Restricted to Cloudflare traffic, with a dedicated client certificate required to authenticate the connection.
Private application
Application services run in a private network. Server-side checks enforce organisation membership.
Protected records
Private databases and file storage, with encryption and permissions limited to the services that need them.
Architecture overview: public HTTPS connections terminate at Cloudflare and the AWS load balancer; application services sit behind it in a restricted private network.
Encryption in transit and at rest
Connections and stored data need their own protection. The Horizons infrastructure design addresses both, with controlled access to encryption keys.
In transit
HTTPS protects browser connections to Cloudflare. Cloudflare connects to the AWS origin over TLS with certificate verification and mutual authentication. The origin accepts TLS 1.2 and 1.3. Database, Redis and file-storage connections also require encrypted transport.
At rest
Database storage, uploaded files, Redis storage and their supported backups are configured for encryption at rest. AWS Key Management Service (KMS) manages the data-encryption keys, with restricted permissions and automatic key rotation. Photos and documents belong in private S3 storage, with public access blocked.
Identity and access
Access starts with a named account and an organisation membership. Signing in alone does not grant access to another organisation’s information.
Protecting accounts
Horizons supports two-factor authentication and passkeys. Passwords are stored as one-way hashes. Rate limits protect sign-in attempts, and sensitive account changes require password confirmation. Invitations are tied to their intended email address and have an expiry.
Limiting access
Organisation membership is checked on the server for each organisation request. API tokens carry an explicit organisation, limited abilities and an expiry; they remain subject to membership checks. Service roles and separate runtime and migration credentials limit what infrastructure and application processes can do.
AWS and Cloudflare, with clear boundaries
The architecture places Cloudflare in front of an AWS load balancer and private application services. Origin access requires both an allowed Cloudflare network address and a trusted client certificate. The database and Redis have no public access, and network rules restrict which services can reach them.
Credentials are held in AWS Secrets Manager. Application services use scoped AWS roles to access storage, rather than embedded AWS access keys. The public marketing website is separate from the application and its recovery records.
Security through the life of the service
Our development workflow includes secret scanning before commits and in CI, pinned dependencies, and automated checks. Infrastructure is defined in version control so configuration changes can be reviewed. The deployment design includes container image scanning, restricted operational logs and service alarms.
Security also depends on maintaining those controls: reviewing access, updating dependencies, rotating credentials and certificates, and responding to alerts. We review operational responsibilities and incident contacts as part of onboarding; provider certifications do not replace that work.
Recovery and data handling
The infrastructure design includes encrypted database backups, point-in-time recovery and versioned file storage. These provide ways to recover from mistakes or disruption. Retention, deletion, restore procedures and recovery expectations need to match the organisation and the information it holds.
We discuss those requirements before a migration, including hosting region and subprocessors. Data-storage location and processing location are distinct: Cloudflare operates a global edge network. Recovery targets must be supported by restore testing before they become service commitments.
Independent assurance of our providers
AWS and Cloudflare maintain independently assessed security programmes. Their reports and certifications provide evidence about the provider controls within each assessment’s scope.
Cloud infrastructure
Amazon Web Services
AWS publishes SOC 2 Type II reports and holds ISO/IEC 27001:2022 certification, alongside ISO 27017 and ISO 27018 certifications for cloud security and protection of personal information. Coverage depends on the service, region and report scope.
Cloudflare maintains a SOC 2 Type II report and ISO/IEC 27001:2022 certification. Its published ISO certifications also include ISO 27018 and ISO 27701 for personal information and privacy management.
Your organisation decides who should have access and how personal information is used. Use individual accounts, enable stronger authentication, review access as people change roles, and protect exported files and staff devices. Collect only what your work requires and agree retention and deletion rules appropriate to your community.
We welcome security and procurement questions. We can discuss the architecture and your requirements, including data handling, access management, recovery and incident communication, before you entrust records to SparkDNA.
Let’s talk about your security requirements.
Bring your questions, procurement requirements or a security questionnaire. We’ll work through them with you.
Contact support@sparkdna.io with a brief description and a way to reach you. Please keep passwords, access tokens and personal recovery records out of the initial email; we can arrange an appropriate way to share sensitive details.
Amazon Web Services, AWS, and the Powered by AWS logo are trademarks of Amazon.com, Inc. or its affiliates. Cloudflare and the Cloudflare logo are trademarks and/or registered trademarks of Cloudflare, Inc. in the United States and other jurisdictions.