No model training on your data
We never train AI models on your data. Our AI subprocessors (OpenAI and Anthropic) are contractually prohibited from training on API customer data and operate under zero-retention agreements where available.
Scallor is built for firms that handle sensitive client engagements. Security and compliance are foundational, not afterthoughts.
6
Standards active
0
PII in app logs
72h
Incident notice
100%
Mutations audited
Six standards enforced today, two in formal audit tracks, two arriving with our Canadian region.
Active today
Enforced now, for every customer
GDPR
EU General Data Protection Regulation
CCPA
California Consumer Privacy Act
CASL
Canadian Anti-Spam Legislation
PIPEDA
Personal Information Protection (Canada)
OWASP Top 10
Secure application development standard
AES-256 & TLS 1.3
Encryption at rest and in transit
In progress
Formal audit track underway
SOC 2 Type II
AICPA Trust Services Criteria
ISO 27001
Information security management aligned
Planned
Lands with the Canadian region
Quebec Law 25
Quebec privacy regulation
PIPA Alberta & BC
Provincial privacy regulations
Six controls, layered like the product itself: isolation at the row, encryption on the wire, and an audit trail that cannot be edited.
Row Level Security
Every database table enforces tenant isolation at the row level. Your organisation can only access its own data, enforced by the database engine.
Encryption at rest & in transit
All data encrypted with AES-256 at rest and TLS 1.3 in transit. Backups encrypted to the same standard.
Defence in depth
Every API request verifies authentication, extracts your organisation, and scopes queries. Multiple layers, no shortcuts.
Immutable audit logging
Every data mutation is logged: user, action, entity, timestamp. Audit logs are append-only and available for compliance review.
No PII in application logs
Server logs contain event types and entity IDs only. Names, emails, and project details never appear in application logs.
How we handle AI
Your AI runs on OpenAI and Anthropic under enterprise agreements that prevent them from training on your data. We manage the keys and list both as subprocessors, so there’s nothing for you to set up, and no model ever learns from your projects.
We never train AI models on your data. Our AI subprocessors (OpenAI and Anthropic) are contractually prohibited from training on API customer data and operate under zero-retention agreements where available.
Granular permissions for owners, delivery leads, and team members. Every action is scoped to a user’s role within their organisation.
Automated dependency and code scanning runs on every change. High-severity issues are triaged within one business day.
Documented procedures for detection, containment, and communication. Customers are notified of any incident affecting their data within 72 hours.
Enterprise SAML and OIDC support is on our roadmap for the post-launch enterprise tier. Today we support secure email one-time codes.
Independent penetration testing planned before general availability and annually thereafter. Reports available on request under NDA.
All customer data is hosted on secure infrastructure in the AWS US East region. GDPR-grade privacy controls protect every data subject regardless of geography.
Every customer gets the same GDPR-grade controls regardless of geography, and storage location is disclosed in every customer agreement.
We are transparent about every vendor with access to customer data. None train models on your data, and all are bound by enterprise-grade data processing agreements.
8
Vendors
0
Train on your data
8/8
Under DPA
Database hosting & authentication. Primary store for all customer data.
Application hosting & deployment. Serves the app; no persistent data store.
AI features under enterprise API agreements. API data excluded from model training.
AI features under enterprise API agreements. API data excluded from model training.
Transactional email delivery: invites, notifications, sign-in links.
Source code hosting & CI/CD. Never receives customer data.
Error tracking & monitoring. PII scrubbed before events leave the app.
Dependency & code vulnerability scanning. Never receives customer data.
See our Privacy Notice and Cookie Policy for how this maps to your rights.
Pilot questions, support, partnerships, anything at all. Your message goes straight to the people building Scallor.