Skip to content

SCOPABLE SECURITY OVERVIEW

Security overview for prospective customers

This concise overview is designed for procurement and security conversations. It summarizes our current public commitments; the Data Processing Agreement, Privacy Policy, and contract documents govern where applicable.

Last updated: August 20, 2026

Data handling and location

Scopable processes Customer Personal Data to provide the services under the customer agreement. Our public DPA states that services are hosted and processed primarily in the United States through Supabase and Vercel infrastructure. Where the GDPR or UK GDPR applies, the DPA provides for appropriate transfer mechanisms, including Standard Contractual Clauses where required.

Customers remain responsible for ensuring they have a lawful basis to provide data to the service. The DPA describes assistance with data-subject requests, security incidents, and return or deletion of Customer Personal Data at the end of the agreement.

Security architecture

  • Multi-tenant application access is scoped with validated tenant context and database access controls.
  • Our public DPA describes TLS 1.2+ encryption in transit and AES-256 encryption at rest through Supabase infrastructure.
  • Application integrations handle credentials through protected server-side controls; credential handling varies by integration and is documented in the applicable product workflow.
  • We maintain technical and organizational measures appropriate to the risk and review controls as services evolve.

Privacy and compliance posture

Scopable publishes a DPA that addresses GDPR, UK GDPR, and CCPA/CPRA roles and obligations. We do not represent a completed SOC 2 Type II certification on this page. Customers with specific requirements should request current documentation and assess it against their own obligations.

Website analytics and cookie choices are described in the Privacy Policy. We do not sell personal information as described there.

Current subprocessors

The following list matches Exhibit B of the public DPA.

SubprocessorPurposeLocation
Supabase, Inc.Database, authentication, and backendUnited States
Vercel, Inc.Frontend hosting and CDNUnited States / Global
PostHog, Inc.Product analyticsUnited States / EU
Stripe, Inc.Payment processing (billing data only)United States

Request documentation

For a security questionnaire, current assessment information, or a procurement follow-up, contact .