Skip to content

SCOPABLE SECURITY OVERVIEW

Security overview for prospective customers

This concise overview is designed for procurement and security conversations. It summarizes our current public commitments; the Data Processing Agreement, Privacy Policy, and contract documents govern where applicable.

Last updated: August 24, 2026

Data handling and location

Scopable processes Customer Personal Data to provide the services under the customer agreement. Our public DPA states that services are hosted and processed primarily in the United States through our infrastructure providers. Where the GDPR or UK GDPR applies, the DPA provides for appropriate transfer mechanisms, including Standard Contractual Clauses where required.

Customers remain responsible for ensuring they have a lawful basis to provide data to the service. Under the DPA, we notify customers of a confirmed security incident within 72 hours of becoming aware of it, and assist with data-subject requests. Customer Data is retained while an account is active and for 30 days after termination to allow export, then deleted.

Security architecture

  • Multi-tenant application access is scoped with validated tenant context and database access controls.
  • Our public DPA describes TLS 1.2+ encryption in transit and AES-256 encryption at rest through our infrastructure providers.
  • Our database runs on PostgreSQL with row-level security enforcing per-tenant isolation at the database layer, hosted on Amazon Web Services (AWS); a global CDN/edge network handles hosting and content delivery.
  • Authentication uses email/password with signed JWT sessions. Passkey (WebAuthn) sign-in — a phishing-resistant, hardware-backed alternative to passwords — is live today in a beta rollout and is expanding toward general availability.
  • Every code change requires peer review and passes automated checks before reaching production.
  • Application integrations handle credentials through protected server-side controls; credential handling varies by integration and is documented in the applicable product workflow.
  • We maintain technical and organizational measures appropriate to the risk and review controls as services evolve.

Privacy and compliance posture

Scopable publishes a DPA that addresses GDPR, UK GDPR, and CCPA/CPRA roles and obligations. We have not completed a SOC 2 Type II audit and do not claim that certification, and we have not yet completed a formal third-party penetration test. Customers with specific requirements should request current documentation and assess it against their own obligations.

Website analytics and cookie choices are described in the Privacy Policy. We do not sell personal information as described there.

Current subprocessors

The following list matches Exhibit B of the public DPA.

SubprocessorPurposeLocation
Supabase, Inc.Database, authentication, and backendUnited States
Vercel, Inc.Frontend hosting and CDNUnited States / Global
Cloudflare, Inc.CDN, DNS, and DDoS/WAF protectionGlobal
PostHog, Inc.Product analyticsUnited States / EU
Postmark (ActiveCampaign, LLC)Transactional email deliveryUnited States
Stripe, Inc.Payment processing (billing data only)United States

Request documentation

For a security questionnaire, current assessment information, or a procurement follow-up, contact .