Trust & Compliance Centre

Your delivery data is always secure.

Scallor is built for firms that handle sensitive client engagements. Security and compliance are foundational, not afterthoughts.

6

Standards active

0

PII in app logs

72h

Incident notice

100%

Mutations audited

Compliance roadmap

Where we stand.

Six standards enforced today, two in formal audit tracks, two arriving with our Canadian region.

Active today

Enforced now, for every customer

  • GDPR

    EU General Data Protection Regulation

  • CCPA

    California Consumer Privacy Act

  • CASL

    Canadian Anti-Spam Legislation

  • PIPEDA

    Personal Information Protection (Canada)

  • OWASP Top 10

    Secure application development standard

  • AES-256 & TLS 1.3

    Encryption at rest and in transit

In progress

Formal audit track underway

  • SOC 2 Type II

    AICPA Trust Services Criteria

  • ISO 27001

    Information security management aligned

Planned

Lands with the Canadian region

  • Quebec Law 25

    Quebec privacy regulation

  • PIPA Alberta & BC

    Provincial privacy regulations

Security practices

How we protect your data.

Six controls, layered like the product itself: isolation at the row, encryption on the wire, and an audit trail that cannot be edited.

Row Level Security

Every database table enforces tenant isolation at the row level. Your organisation can only access its own data, enforced by the database engine.

Encryption at rest & in transit

All data encrypted with AES-256 at rest and TLS 1.3 in transit. Backups encrypted to the same standard.

Defence in depth

Every API request verifies authentication, extracts your organisation, and scopes queries. Multiple layers, no shortcuts.

Immutable audit logging

Every data mutation is logged: user, action, entity, timestamp. Audit logs are append-only and available for compliance review.

No PII in application logs

Server logs contain event types and entity IDs only. Names, emails, and project details never appear in application logs.

How we handle AI

Your AI runs on OpenAI and Anthropic under enterprise agreements that prevent them from training on your data. We manage the keys and list both as subprocessors, so there’s nothing for you to set up, and no model ever learns from your projects.

Operational security

How we run a secure service.

Active

No model training on your data

We never train AI models on your data. Our AI subprocessors (OpenAI and Anthropic) are contractually prohibited from training on API customer data and operate under zero-retention agreements where available.

Active

Role-based access control

Granular permissions for owners, delivery leads, and team members. Every action is scoped to a user’s role within their organisation.

Active

Vulnerability scanning

Automated dependency and code scanning runs on every change. High-severity issues are triaged within one business day.

Active

Incident response plan

Documented procedures for detection, containment, and communication. Customers are notified of any incident affecting their data within 72 hours.

Planned

Single sign-on (SSO)

Enterprise SAML and OIDC support is on our roadmap for the post-launch enterprise tier. Today we support secure email one-time codes.

Planned

Third-party penetration testing

Independent penetration testing planned before general availability and annually thereafter. Reports available on request under NDA.

Data residency

Where your data lives.

aws / us-east-1LIVE

United States · US East

N. Virginia

All customer data is hosted on secure infrastructure in the AWS US East region. GDPR-grade privacy controls protect every data subject regardless of geography.

AES-256 at restTLS 1.3 in transitTenant-isolated (RLS)
aws / roadmapPLANNED

Additional regions

Prioritised by customer demand
  • Canadaca-central-1By demand
  • UK / EUeu-west-2By demand
  • Asia-Pacificap-southeast-1By demand

Every customer gets the same GDPR-grade controls regardless of geography, and storage location is disclosed in every customer agreement.

Subprocessors

Third parties that touch your data.

We are transparent about every vendor with access to customer data. None train models on your data, and all are bound by enterprise-grade data processing agreements.

8

Vendors

0

Train on your data

8/8

Under DPA

SupabaseInfrastructure

Database hosting & authentication. Primary store for all customer data.

us-east-1DPA
VercelInfrastructure

Application hosting & deployment. Serves the app; no persistent data store.

USDPA
OpenAIAI inference

AI features under enterprise API agreements. API data excluded from model training.

USDPANo training
AnthropicAI inference

AI features under enterprise API agreements. API data excluded from model training.

USDPANo training
ResendEmail

Transactional email delivery: invites, notifications, sign-in links.

USDPA
GitHubTooling

Source code hosting & CI/CD. Never receives customer data.

USNo customer data
SentryMonitoring

Error tracking & monitoring. PII scrubbed before events leave the app.

USDPA
SnykSecurity

Dependency & code vulnerability scanning. Never receives customer data.

USNo customer data

See our Privacy Notice and Cookie Policy for how this maps to your rights.

Contact

Something on your mind?

Pilot questions, support, partnerships, anything at all. Your message goes straight to the people building Scallor.

We'll only use your details to respond to you. No newsletter, no drip sequence. Privacy Policy