Trust & Compliance Centre
Your delivery data is always secure.
Scallor is built for firms that handle sensitive client engagements. Security and compliance are foundational, not afterthoughts.
Compliance roadmap
Where we stand.
Hover over any status badge to see details about our compliance posture.
GDPR
ActiveEU General Data Protection Regulation
CCPA
ActiveCalifornia Consumer Privacy Act
CASL
ActiveCanadian Anti-Spam Legislation
PIPEDA
ActivePersonal Information Protection (Canada)
OWASP Top 10
ActiveSecure application development standard
AES-256 & TLS 1.3
ActiveEncryption at rest and in transit
SOC 2 Type II
In progressAICPA Trust Services Criteria
ISO 27001
In progressInformation security management aligned
Quebec Law 25
PlannedQuebec privacy regulation
PIPA Alberta & BC
PlannedProvincial privacy regulations
Security practices
How we protect your data.
Row Level Security
Every database table enforces tenant isolation at the row level. Your organisation can only access its own data, enforced by the database engine.
Encryption at rest & in transit
All data encrypted with AES-256 at rest and TLS 1.3 in transit. Backups encrypted to the same standard.
Defence in depth
Every API request verifies authentication, extracts your organisation, and scopes queries. Multiple layers, no shortcuts.
Immutable audit logging
Every data mutation is logged: user, action, entity, timestamp. Audit logs are append-only and available for compliance review.
No PII in application logs
Server logs contain event types and entity IDs only. Names, emails, and project details never appear in application logs.
AI subprocessor controls
AI features run on OpenAI and Anthropic under enterprise-grade API agreements. Both providers are listed as subprocessors and contractually prohibited from training on your data.
Operational security
How we run a secure service.
No model training on your data
We never train AI models on your data. Our AI subprocessors (OpenAI and Anthropic) are contractually prohibited from training on API customer data and operate under zero-retention agreements where available.
Role-based access control
Granular permissions for owners, delivery leads, and team members. Every action is scoped to a user's role within their organisation.
Vulnerability scanning
Automated dependency and code scanning runs on every change. High-severity issues are triaged within one business day.
Incident response plan
Documented procedures for detection, containment, and communication. Customers are notified of any incident affecting their data within 72 hours.
Single sign-on (SSO)
Enterprise SAML and OIDC support is on our roadmap for the post-launch enterprise tier. Today we support secure email one-time codes.
Third-party penetration testing
Independent penetration testing planned before general availability and annually thereafter. Reports available on request under NDA.
Data residency
Where your data lives.
United States · US East
All customer data is hosted on secure infrastructure in the AWS US East (N. Virginia) region. GDPR-grade privacy controls protect every data subject regardless of geography.
Canada · coming soon
A dedicated Canadian region is on our roadmap. Today, Canadian customers benefit from the same GDPR-grade controls applied to all data. Data storage location is disclosed transparently in every customer agreement.
Subprocessors
Third parties that touch your data.
We are transparent about every vendor with access to customer data. None train models on your data, and all are bound by enterprise-grade data processing agreements.
Supabase
Database hosting & authentication
AWS US East (N. Virginia)
OpenAI
AI inference (no training on customer data)
United States
Anthropic
AI inference (no training on customer data)
United States
Google Drive
Customer-authorised document source with read-only access to the specific folders you select via the Google Picker (drive.file, least-privilege). Selected documents' extracted text + embeddings are indexed; original files are never copied.
United States
Questions about security?
We take security inquiries seriously and respond within one business day.
Contact security team