SCOPABLE SECURITY OVERVIEW
Security overview for prospective customers
This concise overview is designed for procurement and security conversations. It summarizes our current public commitments; the Data Processing Agreement, Privacy Policy, and contract documents govern where applicable.
Last updated: August 24, 2026
Data handling and location
Scopable processes Customer Personal Data to provide the services under the customer agreement. Our public DPA states that services are hosted and processed primarily in the United States through our infrastructure providers. Where the GDPR or UK GDPR applies, the DPA provides for appropriate transfer mechanisms, including Standard Contractual Clauses where required.
Customers remain responsible for ensuring they have a lawful basis to provide data to the service. Under the DPA, we notify customers of a confirmed security incident within 72 hours of becoming aware of it, and assist with data-subject requests. Customer Data is retained while an account is active and for 30 days after termination to allow export, then deleted.
Security architecture
- Multi-tenant application access is scoped with validated tenant context and database access controls.
- Our public DPA describes TLS 1.2+ encryption in transit and AES-256 encryption at rest through our infrastructure providers.
- Our database runs on PostgreSQL with row-level security enforcing per-tenant isolation at the database layer, hosted on Amazon Web Services (AWS); a global CDN/edge network handles hosting and content delivery.
- Authentication uses email/password with signed JWT sessions. Passkey (WebAuthn) sign-in — a phishing-resistant, hardware-backed alternative to passwords — is live today in a beta rollout and is expanding toward general availability.
- Every code change requires peer review and passes automated checks before reaching production.
- Application integrations handle credentials through protected server-side controls; credential handling varies by integration and is documented in the applicable product workflow.
- We maintain technical and organizational measures appropriate to the risk and review controls as services evolve.
Privacy and compliance posture
Scopable publishes a DPA that addresses GDPR, UK GDPR, and CCPA/CPRA roles and obligations. We have not completed a SOC 2 Type II audit and do not claim that certification, and we have not yet completed a formal third-party penetration test. Customers with specific requirements should request current documentation and assess it against their own obligations.
Website analytics and cookie choices are described in the Privacy Policy. We do not sell personal information as described there.
Current subprocessors
The following list matches Exhibit B of the public DPA.
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase, Inc. | Database, authentication, and backend | United States |
| Vercel, Inc. | Frontend hosting and CDN | United States / Global |
| Cloudflare, Inc. | CDN, DNS, and DDoS/WAF protection | Global |
| PostHog, Inc. | Product analytics | United States / EU |
| Postmark (ActiveCampaign, LLC) | Transactional email delivery | United States |
| Stripe, Inc. | Payment processing (billing data only) | United States |
Request documentation
For a security questionnaire, current assessment information, or a procurement follow-up, contact ….