🔒 Security & Trust

Your claims data, handled with care.

ScopeCheck was built inside a working restoration company — we handle the same sensitive claim documents you do, and we protect them the way we'd want ours protected. This page explains exactly how.

Last updated July 2026 · Questions? security@scopecheck.com

At a glance

How we protect your data

Six commitments that define how ScopeCheck treats every estimate you upload.

🛡️

Personal data is redacted before AI ever sees it

Names, street addresses, phone numbers, and claim & policy numbers are stripped from your estimates on the way in — before any analysis runs. The AI works on scope and dollars, not identities.

🗂️

Your files aren't kept

Uploaded estimates are processed transiently and not retained as raw files. We keep the reconciliation result you create — not a library of your source documents.

🏢

Strict tenant isolation

Every request is checked against your organization before any data is read or written. One company can never see another's claims — enforced in the application and backstopped at the database.

🔐

Encrypted, everywhere

All data is encrypted in transit (TLS) and at rest, on SOC 2-attested infrastructure. Sign-in is passwordless — a one-time emailed code — so there's no password to steal.

💳

We never touch your card

All payments run through Stripe. Card details go straight to Stripe and are never stored on ScopeCheck's systems.

🤖

AI with guardrails

Analysis uses a leading U.S. AI provider under commercial terms that prohibit training on your data. Combined with up-front redaction, your claims never become someone's training set.

The detail

Data handling & privacy

Access control & authentication

Infrastructure & monitoring

Subprocessors

Who we rely on

ScopeCheck uses a small set of established, security-attested providers. Their compliance reports are available to enterprise customers under NDA on request.

ProviderPurposeCompliance
VercelApplication hostingSOC 2 Type II
SupabaseDatabase, authentication, file storageSOC 2
StripePayment processingSOC 2 / PCI DSS Level 1
AnthropicAI document analysisSOC 2 Type II
Using SOC 2-attested infrastructure secures the layers those providers manage. ScopeCheck implements and is responsible for its own application-level controls — the practices described on this page.
Compliance

Where we stand on SOC 2

ScopeCheck is built to SOC 2 principles today — least-privilege access, encryption, monitoring, tenant isolation, and vendor management are all in place — and we operate on SOC 2-attested infrastructure. A formal SOC 2 examination is on our roadmap and we pursue it in step with enterprise customer needs. For procurement teams evaluating us now, this page plus a completed security questionnaire is our standard package; reach out and we'll turn one around quickly.

Talk to us about security

Security questionnaire, subprocessor reports under NDA, or a specific control question — we're responsive and we don't hide the ball.

Email security@scopecheck.com

This page describes ScopeCheck's security practices as of the date shown and is provided for informational purposes; it is not a warranty or a contract. Compliance statuses of third-party providers are maintained by those providers. For contractual data-protection terms, see our Privacy Policy and Terms of Service.