Live demo mode. AI dispatches return fictional vendor cards. Real transactions launching with first pilot partners. Terms of Service and Privacy Policy in counsel review; drafts available on request via contact.

scope::security

Security review, self-serve.

Pre-filled SIG Lite, CAIQ Lite, and VRM questionnaires, plus a one-page posture overview. Every answer reflects Scope's actual current build. Items not yet in place are flagged for the post-launch roadmap (target Q3-Q4 2026), not glossed over.

Encryption

TLS 1.2+ in transit. AES-256 at rest. AES-256-GCM for secrets. API tokens stored as SHA-256 hashes, never plaintext.

Tenant isolation

Row Level Security on every tenant-scoped table. Cross-tenant reads blocked at the database layer, not just the application.

Access control

OAuth 2.0 access tokens scope every request to one tenant. RBAC with five roles, capability-based gating. SSO via SAML 2.0 and OIDC.

Audit logging

Append-only tenant-scoped audit log on every mutation: actor, IP, user agent, before and after state. Exportable as CSV and PDF.

Certifications

SOC 2 Type I in progress with Vanta, expected H2 2026. Type II to follow after Type I issuance. HIPAA BAA available on the claims vertical, per vendor at onboarding. The legal vertical does not process PHI. For anything not covered here, email security@scope.bid.