Security
Built to assess external risk — held to the same standard ourselves.
SCARP runs in a managed cloud environment with a dedicated database, encrypted secrets, and tenant isolation enforced in the application and database layers.
Assurance status
Clear status before the control details
SCARP currently has no SOC 2 report, no ISO 27001 certificate, no third-party attestation, and no completed external penetration test.
Detailed architecture and control-review material can be requested during vendor review. Applicable service-provider classifications, the subprocessor register, and data-processing terms are confirmed for the engagement through the contact page.
Controls we operate
Product controls
Tenant isolation by default
Tenant-scoped access checks are backed by database row-level security, role-based permissions, and audited privileged access.
SSRF-safe scanning
Scan targets are validated when work is admitted and again at execution. Private, loopback, link-local, and cloud-metadata destinations are blocked.
Encryption at rest
Application secrets are encrypted under a dedicated key, and platform data is encrypted at rest by the cloud storage and database layers.
Hardened auth
Secure server-side sessions, OIDC SSO, hashed tenant API keys, and role-based access protect product accounts.
HTTPS-only integrations
Webhooks and notifications require HTTPS, use signed delivery, and revalidate destinations when a request is sent.
RBAC & audit
Role-based access and structured security-event logging cover authentication, authorization changes, lockouts, and privileged operations.
Public vendor-review summary
Material service providers and data recipients
Current as of . This public summary identifies the material services that may receive customer, account, billing, or visitor data. Public intelligence sources used to assess a customer's external footprint are listed separately because they are data recipients, not necessarily SCARP subprocessors.
Contractual classifications, legal entities, transfer terms, the detailed provider register, and data-processing terms can be requested and must be confirmed during vendor review through the contact page.
Platform and business services
| Provider | Role | Data boundary |
|---|---|---|
| Google Cloud (Google LLC) | Cloud Run, Cloud SQL, Secret Manager, Cloud Storage, Cloud Logging, Cloud Build, Artifact Registry, Cloud Monitoring, and Cloud Tasks | Receives all application data. Processing is in one region: us-central1 (Iowa, USA). |
| Resend, Inc. | Transactional email | Receives recipient addresses and notification content. |
| Cloudflare, Inc. | Turnstile bot check on the public contact form | Processes the visitor's IP address and browser or device signals to produce a challenge result. It receives no assessment data, tenant data, contact-form content, or authenticated product session data. |
| Anthropic, PBC | Claude API for compliance analysis | Receives customer-uploaded compliance document content only when the tenant enables this integration; it is opt-in and disabled by default. |
| PayProGlobal | Hosted checkout and merchant of record | Processes the billing and payment details submitted at hosted checkout. SCARP receives subscription and invoice identifiers plus sanitized reconciliation records; payment-instrument data does not reach SCARP. |
Public-source categories contacted by a default passive assessment
The detailed provider and query matrix can be requested and confirmed during vendor review. Publicly, SCARP discloses the category and the customer data that can cross each boundary.
| Category | Input crossing the boundary |
|---|---|
| Certificate and transparency | Customer domain name |
| Internet exposure and host intelligence | Customer domain name and/or resolved public IPs |
| DNS resolution | Customer domain name |
| DNS reputation | Resolved public IP encoded in the query name |
| Routing and ASN | Customer ASN and prefix |
| Archived pages | Customer domain name |
| Technology-linked vulnerability intelligence | Technology fingerprints |
Optional provider categories
These integrations are disabled by default and are used only when enabled for the relevant assessment. The detailed provider list and data-flow matrix can be requested and confirmed during vendor review.
| Category | Input crossing the boundary |
|---|---|
| Breach intelligence | Customer domain and, where the integration requires it, synthesized role-based email addresses at that domain |
| Host, threat, contact, and code intelligence | The query data required by the configured provider and the enabled assessment |
Data location and retention
One region, published retention windows
SCARP processes application data in a single Google Cloud region, us-central1 (Iowa, USA). There is no EU region and no customer-selectable data residency.
| Record type | Window |
|---|---|
| Scan results and findings | 730 days |
| Audit log | 730 days |
| Content snapshots | 365 days in the database; 180-day object-storage lifecycle |
| Reports | 30 days in the database; 365-day bucket lifecycle |
| Scan tasks | 90 days |
| Compliance documents and analyses | 1095 days |
| Auth and activity events | 365 days |
| Assistant history | 30 days by default |
On termination, purge occurs within 30 days. This table describes the normal retention schedule; because automated object-storage lifecycle rules operate separately from application legal holds, any legal-hold or custom-retention requirement must be reviewed and agreed before onboarding.
Allowlisting and traffic identification
Coordinate the authorized assessment window
IP allowlisting is not supported today. Active assessment traffic currently originates from dynamic cloud egress, and a guaranteed product signature is not available, so customers cannot reliably identify every request by source IP or header.
Authorization comes from the customer contract and agreed target scope, together with the verification and approval controls enabled for the relevant workflow. Customers should provide their SOC with the authorized domains and assessment window when they want to avoid unnecessary triage.
If detection testing without advance SOC notification is an assessment objective, it requires separate written approval and a documented escalation path. The fuller run sequence is documented on How We Scan.
Responsible disclosure: send a private report to security@getscarp.com with the subject “Private security disclosure.” Do not include customer data or active exploit traffic.