Last updated: 6 August 2026

Spartan Scanning Solutions captures detailed data inside working industrial facilities. Steel mills, recycling operations, and manufacturing plants trust us with information about how their sites are built and how they run. Protecting that information is part of the job, not an afterthought.

This page explains how we do it. If you are evaluating us as a vendor and need more detail than this page provides, contact us and we will walk you through it.

Our security program

We run a formal information security program built on the SOC 2 framework, and we are pursuing SOC 2 Type II attestation. Our controls are monitored continuously through Vanta.

We maintain written policies covering access control, data management, cryptography, incident response, business continuity and disaster recovery, secure development, physical security, operations security, third-party management, and risk management. Every policy is formally approved, reviewed at least annually, and acknowledged by our personnel.

Your facility data

Point clouds, models, imagery, and anything else we capture at your site are treated as confidential and handled under your signed services agreement.

  • Client data is encrypted in transit and at rest.
  • Processed project data is hosted on Cintoo, a platform that holds its own SOC 2 Type II attestation.
  • Access is limited to people who need it for your project and is reviewed on a regular schedule.
  • We do not use client facility data for marketing or publish it without written permission.

Access control

  • Access follows least privilege. People get what their role requires and nothing more.
  • Multi-factor authentication is enforced across our identity provider and business-critical systems.
  • Onboarding and offboarding are documented processes, and access is revoked promptly when someone leaves.
  • Credentials are held in a company password manager rather than in personal notes or shared files.

Devices and people

  • Company computers are monitored for security configuration including disk encryption, screen lock, and password management.
  • Personnel complete security awareness training and acknowledge our policies.
  • Field personnel work under written safety programs and follow each host facility’s site rules.

Vulnerability management

We run recurring external vulnerability scanning against our internet-facing systems, with findings synchronized into our compliance platform. An independent penetration test was performed in 2026. Findings are triaged with a documented disposition and a review date, and remediation is tracked to closure.

Incident response

We maintain a documented incident response plan and a business continuity and disaster recovery plan, both tested periodically. If a security incident affects your data, we will notify you consistent with our contractual and legal obligations.

Vendors

Third parties that touch our systems or data are assessed before use and tracked in a vendor risk program, with a named owner accountable for each one.

Reporting a security concern

If you believe you have found a security vulnerability, or you suspect an incident involving Spartan systems or data, tell us.

Email: anthony@spartanscan.com
Phone: 888-354-SCAN

We take every report seriously and will acknowledge it promptly. We will not pursue action against anyone who reports a genuine vulnerability in good faith and does not access, alter, or destroy data in the process.

Questions from customers and prospects

If you need a security questionnaire completed, a copy of our attestation once it is issued, or a conversation with someone who can answer technical questions, use our contact page and mention security in your message.