Trust & Compliance Centre

Your delivery data, secure by design.

Scallor is built for firms that handle sensitive client engagements. Security and compliance are foundational, not afterthoughts.

6

Standards active

0

PII in app logs

72h

Incident notice

100%

Mutations audited

Compliance roadmap

Where we stand.

Six standards enforced today, three on our roadmap, and two planned that arrive with our Canadian region. We hold no certifications yet. The active items are the controls and standards we operate now, and the certifications we are pursuing sit on our roadmap.

Active today

Enforced now, for every customer

  • GDPR

    EU General Data Protection Regulation

  • CCPA

    California Consumer Privacy Act

  • CASL

    Canadian Anti-Spam Legislation

  • PIPEDA

    Personal Information Protection (Canada)

  • OWASP Top 10

    Secure application development standard

  • AES-256 and TLS 1.3

    Encryption at rest and in transit

On our roadmap

Certifications we are working toward

  • SOC 2 Type I

    AICPA Trust Services Criteria

  • ISO 27001

    Information security management aligned

  • ISO 42001

    AI management system (emerging standard)

Planned

Lands with the Canadian region

  • Quebec Law 25

    Quebec privacy regulation

  • PIPA Alberta & BC

    Provincial privacy regulations

Security practices

How we protect your data.

Six controls, layered like the product itself: isolation at the row, encryption on the wire, and an audit trail that cannot be edited.

Row Level Security

Every database table enforces tenant isolation at the row level. Your organisation can only access its own data, enforced by the database engine.

Encryption at rest and in transit

All data encrypted with AES-256 at rest and TLS 1.3 in transit. Backups encrypted to the same standard.

Defence in depth

Every API request verifies authentication, extracts your organisation, and scopes queries. Multiple layers, no shortcuts.

Immutable audit logging

Every data mutation is logged: user, action, entity, timestamp. Audit logs are append-only and available for compliance review.

No PII in application logs

Server logs contain event types and entity IDs only. Names, emails, and project details never appear in application logs.

How we handle AI

Your AI runs on OpenAI and Anthropic under their API terms, which exclude API customer data from model training. We manage the keys and list both as subprocessors, so there’s nothing for you to set up, and no model ever learns from your projects.

Operational security

How we run a secure service.

Active

No model training on your data

We never train AI models on your data. Our AI subprocessors (OpenAI and Anthropic) are contractually prohibited from training on API customer data and operate under zero-retention agreements where available.

Active

Role-based access control

Granular permissions for owners, delivery leads, and team members. Every action is scoped to a user’s role within their organisation.

Active

Vulnerability scanning

Automated dependency and code scanning runs on every change. High-severity issues are triaged within one business day.

Active

Incident response plan

Documented procedures for detection, containment, and communication. Customers are notified of any incident affecting their data within 72 hours.

Planned

Single sign-on (SSO)

Enterprise SAML and OIDC support is on our roadmap for the post-launch enterprise tier. Today we support secure email one-time codes.

Planned

Third-party penetration testing

Independent penetration testing planned before general availability and annually thereafter. Reports available on request under NDA.

Data residency

Where your data lives.

aws / us-east-1LIVE

United States · US East

N. Virginia

All customer delivery data is hosted on secure infrastructure in the AWS US East region. GDPR-grade privacy controls protect every data subject regardless of geography.

AES-256 at restTLS 1.3 in transitTenant-isolated (RLS)
aws / roadmapPLANNED

Additional regions

Prioritised by customer demand
  • Canadaca-central-1By demand
  • UK / EUeu-west-2By demand
  • Asia-Pacificap-southeast-1By demand

Every customer gets the same GDPR-grade controls regardless of geography, and storage location is disclosed in every customer agreement.

Subprocessors

Third parties that touch your data.

We are transparent about every vendor with access to customer data. None train models on your data, and all are bound by enterprise-grade data processing agreements.

15

Vendors

0

Train on your data

14/15

Under DPA

Infrastructure5

Supabase

Database hosting & authentication. Primary store for all customer data.

us-east-1DPA
Vercel

Application hosting & deployment. Serves the app; no persistent data store.

USDPA
Amazon Web Services

Underlying cloud infrastructure that Supabase and Vercel run on. We hold no direct relationship; listed for transparency about where data physically sits.

us-east-1Via Supabase
Cloudflare

DNS and edge network for scallor.com. Processes request metadata and visitor IP addresses in transit. No customer application data.

Global edgeDPA
Hostinger

Hosting for the scallor.com marketing site. Server access logs only. The product itself does not run here.

USDPA

AI inference2

OpenAI

AI features under OpenAI’s standard API terms, which exclude API customer data from model training.

USDPANo training
Anthropic

AI features under Anthropic’s standard API terms, which exclude API customer data from model training.

USDPANo training

Email1

Resend

Transactional email delivery: invites, notifications, sign-in links.

USDPA

Analytics2

Google Analytics

Aggregated website usage measurement on scallor.com. Analytics cookies are set only after you accept in the cookie banner. Not used in the platform.

USDPAConsent-gated
Microsoft Clarity

Heatmaps and session replay on scallor.com. Loads only after analytics consent. Not used in the platform.

USDPAConsent-gated

Tooling2

Salesforce

Our CRM. Stores enquiries and estimates submitted through forms and resources on scallor.com, such as the ROI calculator, so our team can respond. Hosted in Canada.

CanadaDPACanadian hosting
GitHub

Source code hosting & CI/CD. Never receives customer data.

USDPANo customer data

Payments1

Stripe

Subscription billing and invoicing. Holds billing contact and payment details. Never receives project data.

USDPANo customer data

Monitoring1

Sentry

Error tracking & monitoring. PII scrubbed before events leave the app.

USDPA

Security1

Snyk

Dependency & code vulnerability scanning. Never receives customer data.

USDPANo customer data

See our Privacy Notice and Cookie Policy for how this maps to your rights.

Contact

Something on your mind?

Pilot questions, support, partnerships, anything at all. Your message goes straight to the people building Scallor.

We'll only use your details to respond to you. No newsletter, no drip sequence. Privacy Policy