SECURITY
Security at ScribeOps
Built security-first. Local redaction, zero data retention, RBAC enforcement, and compliance-ready audit trails.
Our Security Philosophy
The architectural decision to redact locally before any cloud processing means your sensitive data never leaves your environment in raw form. ScribeOps was designed so that even in the worst-case scenario of a full breach of our infrastructure, no customer chat content could be exposed — because we never had it.
Data Flow
Your Slack
Thread detected via Slack Events API
Your environmentLocal Redaction
PII/secrets stripped by sidecar container
Your environmentScribeOps Cloud
Sanitized text structured into runbook
ScribeOpsYour Wiki
Published via OAuth to Notion/Confluence
Your environmentSOC 2 Type II
In ProgressControls mapped to Trust Service Criteria. Audit scheduled.
Target: Q1 2026
ISO 27001
In ProgressISMS documentation complete. Certification audit pending.
Target: Q2 2026
GDPR
CompliantData Processing Agreement available. Right to erasure supported.
Target: Active
Penetration Testing
CompleteAnnual third-party pentest. No critical findings.
Target: Last: July 2025
Policies & Resources
Data Retention Policy
Zero retention of raw chat content. Processed data deleted within 30 seconds of extraction.
Vulnerability Disclosure
Report security issues to security@scribeops.com. PGP key available on request.
Enterprise Security Addendum
Custom security agreements available for Enterprise customers.