SECURITY

Security at ScribeOps

Built security-first. Local redaction, zero data retention, RBAC enforcement, and compliance-ready audit trails.

Our Security Philosophy

The architectural decision to redact locally before any cloud processing means your sensitive data never leaves your environment in raw form. ScribeOps was designed so that even in the worst-case scenario of a full breach of our infrastructure, no customer chat content could be exposed — because we never had it.

Data Flow

Step 1

Your Slack

Thread detected via Slack Events API

Your environment
Step 2

Local Redaction

PII/secrets stripped by sidecar container

Your environment
Step 3

ScribeOps Cloud

Sanitized text structured into runbook

ScribeOps
Step 4

Your Wiki

Published via OAuth to Notion/Confluence

Your environment

SOC 2 Type II

In Progress

Controls mapped to Trust Service Criteria. Audit scheduled.

Target: Q1 2026

ISO 27001

In Progress

ISMS documentation complete. Certification audit pending.

Target: Q2 2026

GDPR

Compliant

Data Processing Agreement available. Right to erasure supported.

Target: Active

Penetration Testing

Complete

Annual third-party pentest. No critical findings.

Target: Last: July 2025

Policies & Resources

Data Retention Policy

Zero retention of raw chat content. Processed data deleted within 30 seconds of extraction.

Vulnerability Disclosure

Report security issues to security@scribeops.com. PGP key available on request.

Enterprise Security Addendum

Custom security agreements available for Enterprise customers.