Skip to content

ScopeMantle is SOC 2 Type II in progress, read our trust commitments →

Trust Center

Trust, verified.

ScopeMantle asks customers to put third parties on a governed footing. We hold ourselves to the same bar, publicly, continuously, auditably.

COMMITMENTS

Six promises we hold ourselves to.

  • We don't sell customer data. Ever.

    Customer data is processed solely to provide the service contracted. It is never sold, brokered, monetized for advertising, or used to train models for any other customer.

  • Read-only by default.

    Every connector ships with read-only OAuth scopes. Write actions, revokes, ticket creation, require an explicit per-tenant toggle in your workspace settings.

  • We publish our sub-processors list.

    The full sub-processors list is public, dated, and versioned. We notify customers in advance of any addition or material change.

  • Data residency is your choice.

    Pick US (us-east-1) or EU (eu-central-1) at provisioning. APAC residency is on the roadmap. Customer data does not cross the region boundary you choose, in transit or at rest.

  • Our DPA is plain-language and pre-countersigned.

    Standard MSA, DPA, and Order Form are pre-signed by our counsel. SCCs are attached for EU transfers. Most customers close legal in under 14 days.

  • Responsible disclosure, real payouts.

    We run a public disclosure program with safe-harbor language and bounty tiers from $100 (Low) to $15,000 (Critical). We acknowledge within one business day.

CURRENT POSTURE

Where we stand today.

Posture snapshot
Updated manually · monthly · last 2026-04-15
Uptime (last 30 days)
99.98%
status.scopemantle.com
SOC 2 Type II progress
82%
Bridge letter under NDA
Last third-party penetration test
March 2026
Full report under NDA
Open security findings
0Critical0High1Medium3Low
All in remediation · changelog
Sub-processors last updated
14 days ago
View sub-processors list
Updated manually monthly. For real-time status see status.scopemantle.com

CONTACTS

How to reach us.

INCIDENT RESPONSE

How we handle a security incident.

Customers notified within 72 hours of confirmed incident per contract; for EU customers, within GDPR Article 33 windows.

  1. 01

    Detect

    24/7 alerting on the ScopeMantle security pipeline, anomalous auth, OAuth grant spikes, failed connector sweeps, and external signals (status providers, threat intel feeds).

  2. 02

    Contain

    On-call SecOps isolates affected components, rotates compromised credentials, and pauses connectors as needed. Customer impact is scoped before notification to avoid speculative disclosures.

  3. 03

    Notify

    Customers notified within 72 hours of confirmed incident per contract; for EU customers, within GDPR Article 33 windows. Notice includes scope, timeline, and the customer-side actions we recommend.

  4. 04

    Remediate

    Fix deployed and verified. Where customer action is required (token rotation, log review), ScopeMantle provides step-by-step guidance and validates completion via the audit log.

  5. 05

    Post-mortem

    Blameless post-mortem published to affected customers within 14 days. Material changes appear on the public security changelog at /security#changelog.

Have specific diligence questions?

Our security team is happy to answer on a call, questionnaires, architecture walkthroughs, or controls deep-dives.