An overview of our security program. Full reports and our SOC 2 are available under NDA from [email protected].
Our security program follows ISO 27001 controls and is audited annually for SOC 2 Type II. We run quarterly penetration tests, monthly vulnerability scans, and weekly dependency reviews. Findings are tracked publicly to our customers on Scale.
SSO (SAML 2.0 and OIDC) on the Scale plan. TOTP-based 2FA on all paid plans. Internal access is just-in-time, requires hardware keys, and is logged. We follow the principle of least privilege — most engineers cannot access customer data without an approved JIT request.
We process customer data only to provide the service. We do not train AI models on your conversations or your customers' conversations. We use third-party LLM providers (currently Anthropic) under zero-data-retention contracts; their API responses are not retained beyond the request.
24/7 on-call rotation. We notify affected customers of confirmed security incidents within 72 hours of discovery, per GDPR Article 33 and our Master Services Agreement.
We welcome reports from security researchers. Submit findings to [email protected] (PGP key on keys.openpgp.org). We commit to a 48-hour first response, a 30-day patch SLA for critical findings, and public acknowledgment if you'd like one.
The current list with locations, purposes, and DPAs is at /dpa. We notify customers 30 days before adding a new sub-processor.