Trust Center
We protect MSP data like it's our own. The tools you trust shouldn't require blind faith, so everything below is stated plainly, including what we haven't done yet.
Posture at a glance
- AES-256
- Encryption at rest
- TLS 1.2+
- Encryption in transit
- Row-level
- Per-tenant isolation
- 72 hours
- Incident notification
Your clients' data sits inside your Scopable tenant. Tenant context is validated at the database layer with row-level security, not just in application code, so a bug in one place can't cross the boundary on its own.
Compliance
Where we are today, stated without hedging. We would rather lose a deal than imply a certification we don't hold.
GDPR & UK GDPR
Our DPA addresses GDPR and UK GDPR processing terms.
Security questionnaires
Security documentation and questionnaires can be requested from our team.
SOC 2 Type II
We have not completed a SOC 2 Type II audit and do not claim that certification.
Third-party penetration test
We have not yet completed a formal third-party penetration test.
Infrastructure & data protection
- Hosting
- Global CDN/edge network, primary hosting in the United States
- Database
- PostgreSQL with row-level security enforcing per-tenant data isolation at the database layer
- Cloud infrastructure
- Amazon Web Services (AWS) underlies our database and CI/CD pipeline
- Encryption at rest
- AES-256
- Encryption in transit
- TLS 1.2+
- Architecture
- Multi-tenant platform with database access controls and tenant-scoped application access
- Tenant isolation
- Tenant context is validated before application data is read or written
- Backups
- Backups run automatically on a recurring schedule, with recovery procedures maintained by our infrastructure providers
Application security
- Authentication
- Email/password with signed JWT sessions. Passkey (WebAuthn) sign-in is live in beta rollout, offering phishing-resistant, hardware-backed authentication
- Authorization
- Tenant-scoped access controls are applied in the application and data layers
- API security
- Authenticated application workflows validate authorization and tenant context
- Source control & CI/CD
- Every change requires peer review and passes automated checks before reaching production
- Dependency management
- Automated dependency vulnerability scanning and patching
- Error monitoring
- Operational monitoring and error reporting support incident response
- Analytics
- Website analytics are subject to the controls described in our Privacy Policy
Data privacy
- Data retention
- Customer Data is retained while your account is active. After termination it stays available for export for 30 days, after which it may be deleted in line with our retention schedules. Some data is kept longer where the law requires it.
- Data deletion
- Within 30 days of termination you may elect in writing to have Personal Data deleted or returned, except where retention is required by applicable law (DPA 3.6).
Subprocessors
This list matches Exhibit B of the public Data Processing Agreement. We notify customers of material changes.
| Vendor | Purpose | Data processed |
|---|---|---|
| Supabase | Database, Auth, Edge Functions | All application data |
| Vercel | Hosting, CDN, Edge Middleware | Request routing, static assets |
| Cloudflare | CDN, DNS, DDoS/WAF protection | Network traffic, request routing |
| PostHog | Product analytics | Usage and analytics data |
| Postmark | Transactional email delivery | Recipient email addresses, email content |
| Stripe | Payments | Billing data |
Operational security
- Technical and organizational measures are maintained to protect personal data.
- Authorized personnel are subject to confidentiality obligations.
- Confirmed security incidents affecting Customer Personal Data are reported to affected customers within 72 hours of Scopable becoming aware, per our DPA.
- We review our controls as our services and providers evolve.
Contact & disclosure
Security inquiries
Questionnaires, architecture questions, or documentation requests. Use the documentation request above to reach the security team.
Responsible disclosure
Report vulnerabilities in good faith. Use the documentation request above to reach the security team.