Legal

Compliance Overview

SparrowHawk CRM's current compliance posture and how we support customer compliance programs.

Effective: July 13, 2026

Last updated: July 13, 2026

Version
v1.0
Effective
July 13, 2026
Last Updated
July 13, 2026

What This Page Is (and Isn't)

This page is maintained by SparrowHawk CRM LLC to answer common compliance questions about the platform. It is not an independent audit report, a certification, or legal advice. Where a compliance program is under active development, it is clearly labeled “Planned” or “Roadmap.” We would rather understate our posture than misrepresent it.

Current Program

  • Encryption in transit (TLS) and at rest for Customer Data.
  • Tenant isolation enforced at the database layer through row-level security.
  • Role-based access control across five defined roles (super admin, organization admin, organization user, FBO admin, FBO user).
  • Append-only audit logging for sensitive administrative actions.
  • Documented Incident Response Policy and Vulnerability Disclosure Policy.
  • Enterprise Data Processing Addendum available on request.
  • Subprocessor register maintained on the Subprocessor List page.
  • PCI DSS scope minimized: card data is handled by Stripe; SparrowHawk CRM does not store full card numbers or card security codes.
  • Data Retention & Deletion Policy with published category-level retention targets.
  • Accessibility program targeting WCAG 2.1 Level AA.

Planned Certifications and Programs

Planned — not yet certified

SparrowHawk CRM LLC intends to pursue the certifications and programs below as the platform matures. These items do not represent current certifications and should not be relied upon as compliance claims.

  • SOC 2 Type II — targeted for a future audit cycle once program readiness is achieved.
  • ISO / IEC 27001 — under evaluation for the mid-term compliance roadmap.
  • Independent third-party penetration testing on a documented cadence.
  • Region-specific privacy attestations as customer demand and program maturity warrant.

How We Support Customer Compliance

Customers who are themselves subject to compliance obligations (privacy regulations, sector-specific rules, insurance requirements, aviation authority requirements) can rely on the following supports:

  • the Data Processing Addendum, which describes SparrowHawk CRM LLC's role as processor
  • the Subprocessor List page and change-notification procedure
  • role-based access control and audit logs that support internal control frameworks
  • export tooling to meet retention or portability obligations
  • the Incident Response Policy and its notification commitments

What Customers Are Responsible For

Compliance is a shared responsibility. Customers are responsible for how they configure their organization, what data they submit, whether they have a lawful basis for processing that data, how they manage user access, and how they respond to their own regulatory obligations. Nothing on this page transfers those responsibilities to SparrowHawk CRM LLC.

Aviation-Specific Note

SparrowHawk CRM is a business management platform. It does not certify aircraft, replace civil aviation authority regulations, replace manufacturer manuals, or authorize return to service. Regulated aviation decisions remain the responsibility of appropriately licensed personnel.

Contact

Compliance questions may be sent to compliance@sparrowhawkcrm.com (or support@sparrowhawkcrm.com if the compliance address is not yet monitored).