Skip to content

Trust Center

We protect MSP data like it's our own. The tools you trust shouldn't require blind faith, so everything below is stated plainly, including what we haven't done yet.

Request security documentationSecurity overview for prospective customers

Posture at a glance

AES-256
Encryption at rest
TLS 1.2+
Encryption in transit
Row-level
Per-tenant isolation
72 hours
Incident notification

Your clients' data sits inside your Scopable tenant. Tenant context is validated at the database layer with row-level security, not just in application code, so a bug in one place can't cross the boundary on its own.

Compliance

Where we are today, stated without hedging. We would rather lose a deal than imply a certification we don't hold.

GDPR & UK GDPR

Our DPA addresses GDPR and UK GDPR processing terms.

In place

Security questionnaires

Security documentation and questionnaires can be requested from our team.

In place

SOC 2 Type II

We have not completed a SOC 2 Type II audit and do not claim that certification.

Not yet

Third-party penetration test

We have not yet completed a formal third-party penetration test.

Not yet

Infrastructure & data protection

Hosting
Global CDN/edge network, primary hosting in the United States
Database
PostgreSQL with row-level security enforcing per-tenant data isolation at the database layer
Cloud infrastructure
Amazon Web Services (AWS) underlies our database and CI/CD pipeline
Encryption at rest
AES-256
Encryption in transit
TLS 1.2+
Architecture
Multi-tenant platform with database access controls and tenant-scoped application access
Tenant isolation
Tenant context is validated before application data is read or written
Backups
Backups run automatically on a recurring schedule, with recovery procedures maintained by our infrastructure providers

Application security

Authentication
Email/password with signed JWT sessions. Passkey (WebAuthn) sign-in is live in beta rollout, offering phishing-resistant, hardware-backed authentication
Authorization
Tenant-scoped access controls are applied in the application and data layers
API security
Authenticated application workflows validate authorization and tenant context
Source control & CI/CD
Every change requires peer review and passes automated checks before reaching production
Dependency management
Automated dependency vulnerability scanning and patching
Error monitoring
Operational monitoring and error reporting support incident response
Analytics
Website analytics are subject to the controls described in our Privacy Policy

Data privacy

Data retention
Customer Data is retained while your account is active. After termination it stays available for export for 30 days, after which it may be deleted in line with our retention schedules. Some data is kept longer where the law requires it.
Data deletion
Within 30 days of termination you may elect in writing to have Personal Data deleted or returned, except where retention is required by applicable law (DPA 3.6).

Subprocessors

This list matches Exhibit B of the public Data Processing Agreement. We notify customers of material changes.

VendorPurposeData processed
SupabaseDatabase, Auth, Edge FunctionsAll application data
VercelHosting, CDN, Edge MiddlewareRequest routing, static assets
CloudflareCDN, DNS, DDoS/WAF protectionNetwork traffic, request routing
PostHogProduct analyticsUsage and analytics data
PostmarkTransactional email deliveryRecipient email addresses, email content
StripePaymentsBilling data

Operational security

  • Technical and organizational measures are maintained to protect personal data.
  • Authorized personnel are subject to confidentiality obligations.
  • Confirmed security incidents affecting Customer Personal Data are reported to affected customers within 72 hours of Scopable becoming aware, per our DPA.
  • We review our controls as our services and providers evolve.

Contact & disclosure

Security inquiries

Questionnaires, architecture questions, or documentation requests. Use the documentation request above to reach the security team.

Responsible disclosure

Report vulnerabilities in good faith. Use the documentation request above to reach the security team.