Security
Last updated August 2, 2026
Mainspring Software LLC builds software that businesses run on. That means holding things that matter to them: customer lists, routes, payments, and access to the social accounts they have spent years building. This page says how we approach that, and what we do and do not claim.
How we build
- Credentials are never collected where a standard exists. Connections to outside services use that service's own sign in, so we receive a revocable token rather than a password.
- Secrets are encrypted before they are stored. Anything that grants access to a customer account is encrypted with AES-256-GCM at rest, and the product refuses to store it at all if encryption is unavailable.
- Every record belongs to one account. Data is scoped by owner and filtered on the server on every request, never in the browser.
- Traffic is encrypted in transit. Our sites and applications are served over HTTPS.
- Dependencies are watched. Our repositories are monitored for known vulnerabilities in the packages they use, and updates are reviewed on a schedule rather than when something breaks.
- Accounts that can ship code use two factor authentication. That includes source control, hosting, and the databases behind each product.
Per product detail
Each product handles different data and states its own specifics. Where a product has a security page, that page is the authority for it.
- Mainspring Social security, covering connected social accounts and how their access tokens are held.
- AquaRoute is distributed through the Apple App Store, which means the app and the company behind it were reviewed by Apple and its data collection is declared publicly on its store listing. That is an accountability check rather than a security audit, and we describe it as exactly that.
What we do not claim
We would rather say this plainly than let a logo imply otherwise. Mainspring Software LLC does not currently hold a SOC 2 report, and none of our products are HIPAA business associates. We are a young company. If either changes we will say so here, on the day it is true and not before.
We do not display certification badges we have not earned, and we do not display awards we have not been given.
Reporting a problem
If you believe you have found a vulnerability in any Mainspring product, email support@mainspringsoftware.com with enough detail to reproduce it. We will confirm we received it, and we will not pursue anyone who reports a genuine issue in good faith and gives us a reasonable chance to fix it before making it public.
The company
Mainspring Software LLC is a registered company based in Pennsylvania, USA. Questions about anything on this page go to hello@mainspringsoftware.com.