Security is foundational to ScanCompliant. Our customers trust us with proprietary marketing content, business information, and user data. We take that responsibility seriously and implement layered security controls across our infrastructure, application, and operations.
This document describes our security posture as of the date above. For enterprise due diligence requests or vendor security questionnaires, contact support@scancompliant.com.
All data stored on our servers is encrypted using AES-256. Database volumes, backups, and file storage are encrypted.
All data transmitted between your browser and our servers is protected by TLS 1.2 or higher. We enforce HTTPS across all endpoints.
Hosted on Google Cloud Platform (GCP), which maintains SOC 2 Type II, ISO 27001, and FedRAMP certifications.
Role-based access control limits employee access to customer data to only those who need it for their role.
MFA is available for all user accounts and required for all ScanCompliant internal systems access.
All access to customer data by ScanCompliant employees is logged and regularly reviewed.
Our platform runs on Google Cloud Platform. GCP data centers maintain physical security controls including 24/7 security personnel, biometric access, and surveillance systems. GCP holds the following certifications: SOC 1/2/3, ISO 27001, ISO 27017, ISO 27018, PCI DSS, and FedRAMP.
Each customer's data is logically isolated at the database level. No customer can access another customer's scan data, reports, or keyword libraries. Isolation is enforced at both the application and database query levels.
URLs, documents, images, and other content you submit for compliance review are:
Clara AI conversations are stored for 90 days to enable conversation history within the platform. They are encrypted at rest, not used to train external AI models, and not reviewed by employees unless you report an issue that requires investigation.
We maintain a documented security incident response plan. In the event of a confirmed data breach affecting customer data:
To report a suspected security incident: support@scancompliant.com
We use the following third-party sub-processors in delivering our services. All are bound by data processing agreements:
| Provider | Purpose | Location |
|---|---|---|
| Google Cloud Platform | Cloud hosting, storage, compute | United States (multi-region) |
| Stripe, Inc. | Payment processing | United States |
| SendGrid (Twilio) | Transactional email delivery | United States |
| Google Analytics | Website usage analytics | United States |
| Intercom | Customer support chat | United States |
| OpenAI / Anthropic | AI model powering Clara AI | United States |
We will notify customers of material changes to our sub-processor list with at least 30 days' notice.
You may request deletion of your account and data at any time by emailing support@scancompliant.com. Account deletion is completed within 30 days. Billing records are retained per legal requirements even after account deletion.
For customers in the European Economic Area (EEA) or United Kingdom, ScanCompliant acts as a data processor with respect to personal data contained in content you submit for review. You act as the data controller.
We are willing to enter into a Data Processing Agreement (DPA) in accordance with GDPR Article 28. Enterprise customers requiring a signed DPA should contact support@scancompliant.com.
International data transfers from the EEA to the United States are conducted under Standard Contractual Clauses (SCCs) approved by the European Commission.
We appreciate the work of security researchers who help keep our platform safe. If you discover a security vulnerability in ScanCompliant, please report it responsibly:
We will acknowledge all reports within 48 hours and will not pursue legal action against good-faith researchers who follow these guidelines.
Security concerns: support@scancompliant.com
Privacy questions: support@scancompliant.com
DPA / GDPR requests: support@scancompliant.com