Skip to main content

Trust & Compliance Centre

Your delivery data is always secure.

Scallor is built for firms that handle sensitive client engagements. Security and compliance are foundational, not afterthoughts.

Compliance roadmap

Where we stand.

Hover over any status badge to see details about our compliance posture.

Active
In progress
Planned

GDPR

Active

EU General Data Protection Regulation

CCPA

Active

California Consumer Privacy Act

CASL

Active

Canadian Anti-Spam Legislation

PIPEDA

Active

Personal Information Protection (Canada)

OWASP Top 10

Active

Secure application development standard

AES-256 & TLS 1.3

Active

Encryption at rest and in transit

SOC 2 Type II

In progress

AICPA Trust Services Criteria

ISO 27001

In progress

Information security management aligned

Quebec Law 25

Planned

Quebec privacy regulation

PIPA Alberta & BC

Planned

Provincial privacy regulations

Security practices

How we protect your data.

Row Level Security

Every database table enforces tenant isolation at the row level. Your organisation can only access its own data, enforced by the database engine.

Encryption at rest & in transit

All data encrypted with AES-256 at rest and TLS 1.3 in transit. Backups encrypted to the same standard.

Defence in depth

Every API request verifies authentication, extracts your organisation, and scopes queries. Multiple layers, no shortcuts.

Immutable audit logging

Every data mutation is logged: user, action, entity, timestamp. Audit logs are append-only and available for compliance review.

No PII in application logs

Server logs contain event types and entity IDs only. Names, emails, and project details never appear in application logs.

AI subprocessor controls

AI features run on OpenAI and Anthropic under enterprise-grade API agreements. Both providers are listed as subprocessors and contractually prohibited from training on your data.

Operational security

How we run a secure service.

Active

No model training on your data

We never train AI models on your data. Our AI subprocessors (OpenAI and Anthropic) are contractually prohibited from training on API customer data and operate under zero-retention agreements where available.

Active

Role-based access control

Granular permissions for owners, delivery leads, and team members. Every action is scoped to a user's role within their organisation.

Active

Vulnerability scanning

Automated dependency and code scanning runs on every change. High-severity issues are triaged within one business day.

Active

Incident response plan

Documented procedures for detection, containment, and communication. Customers are notified of any incident affecting their data within 72 hours.

Planned

Single sign-on (SSO)

Enterprise SAML and OIDC support is on our roadmap for the post-launch enterprise tier. Today we support secure email one-time codes.

Planned

Third-party penetration testing

Independent penetration testing planned before general availability and annually thereafter. Reports available on request under NDA.

Data residency

Where your data lives.

United States · US East

All customer data is hosted on secure infrastructure in the AWS US East (N. Virginia) region. GDPR-grade privacy controls protect every data subject regardless of geography.

Canada · coming soon

A dedicated Canadian region is on our roadmap. Today, Canadian customers benefit from the same GDPR-grade controls applied to all data. Data storage location is disclosed transparently in every customer agreement.

Subprocessors

Third parties that touch your data.

We are transparent about every vendor with access to customer data. None train models on your data, and all are bound by enterprise-grade data processing agreements.

Supabase

Database hosting & authentication

AWS US East (N. Virginia)

OpenAI

AI inference (no training on customer data)

United States

Anthropic

AI inference (no training on customer data)

United States

Google Drive

Customer-authorised document source with read-only access to the specific folders you select via the Google Picker (drive.file, least-privilege). Selected documents' extracted text + embeddings are indexed; original files are never copied.

United States

Questions about security?

We take security inquiries seriously and respond within one business day.

Contact security team