Skip to content

Security

Built to assess external risk — held to the same standard ourselves.

SCARP runs in a managed cloud environment with a dedicated database, encrypted secrets, and tenant isolation enforced in the application and database layers.

Assurance status

Clear status before the control details

SCARP currently has no SOC 2 report, no ISO 27001 certificate, no third-party attestation, and no completed external penetration test.

Detailed architecture and control-review material can be requested during vendor review. Applicable service-provider classifications, the subprocessor register, and data-processing terms are confirmed for the engagement through the contact page.

Controls we operate

Product controls

  • Tenant isolation by default

    Tenant-scoped access checks are backed by database row-level security, role-based permissions, and audited privileged access.

  • SSRF-safe scanning

    Scan targets are validated when work is admitted and again at execution. Private, loopback, link-local, and cloud-metadata destinations are blocked.

  • Encryption at rest

    Application secrets are encrypted under a dedicated key, and platform data is encrypted at rest by the cloud storage and database layers.

  • Hardened auth

    Secure server-side sessions, OIDC SSO, hashed tenant API keys, and role-based access protect product accounts.

  • HTTPS-only integrations

    Webhooks and notifications require HTTPS, use signed delivery, and revalidate destinations when a request is sent.

  • RBAC & audit

    Role-based access and structured security-event logging cover authentication, authorization changes, lockouts, and privileged operations.

Public vendor-review summary

Material service providers and data recipients

Current as of . This public summary identifies the material services that may receive customer, account, billing, or visitor data. Public intelligence sources used to assess a customer's external footprint are listed separately because they are data recipients, not necessarily SCARP subprocessors.

Contractual classifications, legal entities, transfer terms, the detailed provider register, and data-processing terms can be requested and must be confirmed during vendor review through the contact page.

Platform and business services

Platform and business services
ProviderRoleData boundary
Google Cloud (Google LLC)Cloud Run, Cloud SQL, Secret Manager, Cloud Storage, Cloud Logging, Cloud Build, Artifact Registry, Cloud Monitoring, and Cloud TasksReceives all application data. Processing is in one region: us-central1 (Iowa, USA).
Resend, Inc.Transactional emailReceives recipient addresses and notification content.
Cloudflare, Inc.Turnstile bot check on the public contact formProcesses the visitor's IP address and browser or device signals to produce a challenge result. It receives no assessment data, tenant data, contact-form content, or authenticated product session data.
Anthropic, PBCClaude API for compliance analysisReceives customer-uploaded compliance document content only when the tenant enables this integration; it is opt-in and disabled by default.
PayProGlobalHosted checkout and merchant of recordProcesses the billing and payment details submitted at hosted checkout. SCARP receives subscription and invoice identifiers plus sanitized reconciliation records; payment-instrument data does not reach SCARP.

Public-source categories contacted by a default passive assessment

The detailed provider and query matrix can be requested and confirmed during vendor review. Publicly, SCARP discloses the category and the customer data that can cross each boundary.

Keyless public assessment sources
CategoryInput crossing the boundary
Certificate and transparencyCustomer domain name
Internet exposure and host intelligenceCustomer domain name and/or resolved public IPs
DNS resolutionCustomer domain name
DNS reputationResolved public IP encoded in the query name
Routing and ASNCustomer ASN and prefix
Archived pagesCustomer domain name
Technology-linked vulnerability intelligenceTechnology fingerprints

Optional provider categories

These integrations are disabled by default and are used only when enabled for the relevant assessment. The detailed provider list and data-flow matrix can be requested and confirmed during vendor review.

Optional provider categories
CategoryInput crossing the boundary
Breach intelligenceCustomer domain and, where the integration requires it, synthesized role-based email addresses at that domain
Host, threat, contact, and code intelligenceThe query data required by the configured provider and the enabled assessment

Data location and retention

One region, published retention windows

SCARP processes application data in a single Google Cloud region, us-central1 (Iowa, USA). There is no EU region and no customer-selectable data residency.

Published retention windows
Record typeWindow
Scan results and findings730 days
Audit log730 days
Content snapshots365 days in the database; 180-day object-storage lifecycle
Reports30 days in the database; 365-day bucket lifecycle
Scan tasks90 days
Compliance documents and analyses1095 days
Auth and activity events365 days
Assistant history30 days by default

On termination, purge occurs within 30 days. This table describes the normal retention schedule; because automated object-storage lifecycle rules operate separately from application legal holds, any legal-hold or custom-retention requirement must be reviewed and agreed before onboarding.

Allowlisting and traffic identification

Coordinate the authorized assessment window

IP allowlisting is not supported today. Active assessment traffic currently originates from dynamic cloud egress, and a guaranteed product signature is not available, so customers cannot reliably identify every request by source IP or header.

Authorization comes from the customer contract and agreed target scope, together with the verification and approval controls enabled for the relevant workflow. Customers should provide their SOC with the authorized domains and assessment window when they want to avoid unnecessary triage.

If detection testing without advance SOC notification is an assessment objective, it requires separate written approval and a documented escalation path. The fuller run sequence is documented on How We Scan.

Responsible disclosure: send a private report to security@getscarp.com with the subject “Private security disclosure.” Do not include customer data or active exploit traffic.