SECURITY

How we look after your data

Where it lives, who can reach it, how machine access is scoped — and, just as plainly, what we do not have yet.

Where your data lives

  • The application runs on Vercel in Frankfurt (fra1), and the database is Postgres on Neon in Frankfurt (AWS eu-central-1).
  • Traffic is encrypted in transit with TLS, and the database is encrypted at rest by its provider.
  • We never delete measurements on our own: a day that was not measured cannot be measured later. When you delete a project or close a workspace, its data is deleted within 30 days.
  • You can export every screen as CSV at any time, without asking us.

Signing in

  • There are no passwords to leak or reuse. You sign in with Google or with a one-time link sent to your email.
  • Invitations are single-use links, stored only as a hash.

Who can see what

  • Every read of product data checks that you belong to the workspace that owns it. A project you do not belong to returns the same “not found” as one that does not exist, so its ID is not confirmed to anyone.
  • Three roles: owner — everything, including billing; admin — everything except billing; member — reads the data, cannot start paid work.
  • Roles are enforced on the server, not only in the interface. A member who finds a hidden button gets a refusal, not a charge.

MCP and API access

  • The MCP server uses OAuth 2.1 with mandatory PKCE. A token is scoped to one workspace and to read or read-and-write.
  • Access tokens expire after 1 hour; refresh tokens after 60 days. Tokens are stored only as a hash.
  • API keys are shown once, when created, and stored only as a SHA-256 hash. You can revoke them at any time.
  • Every tool that changes something — adding a prompt, posting to Slack, saving a Doc — first returns a plan and does nothing until it is confirmed.

The agent

  • It never publishes. Everything it writes is saved as a draft in your workspace.
  • It runs under the credit ceiling you set, and every session is recorded with what it read and what it cost.
  • Tools it can send work to (Slack, Google Docs, Gmail, Notion) are connected by you, belong to your workspace, and can be disconnected at any time. Gmail gets drafts, never sent email.

Payments

  • Paddle is our Merchant of Record. Card details are entered in Paddle's checkout and never reach our servers.

Your data and AI models

  • We do not use your prompts, measurements or agent sessions to train models of our own.
  • Answers are analysed and the agent runs on Anthropic's API, under their commercial terms.

Abuse protection

  • Public forms — the free scan and the contact form — are protected by Vercel BotID and rate limits per IP address, stored as a salted hash rather than the address itself.

What we do not have yet

We are not SOC 2 or ISO 27001 certified, and we do not offer SSO/SAML or SCIM today. If your procurement needs them, tell us before you buy — on a custom plan we will answer your security questionnaire and say which items we can meet and which we cannot.

Talk to us about a custom plan

Found a vulnerability?

Write to support@getscorra.com with the steps to reproduce it. Please give us a reasonable time to fix it before making it public. We do not take legal action against good-faith research.