We treat your client data like it's our own.
ScopePilot is built for agencies that handle confidential client information every day — pitches, brand strategy, internal numbers. Here's exactly how we keep it safe.
How we protect your data
EU-hosted by default
Your account, briefs, proposals, and uploaded files are stored on EU-region infrastructure. Limited operational data may be processed by EU or US sub-processors under Standard Contractual Clauses — see the list below.
Encrypted in transit & at rest
Every connection uses TLS 1.2+. All databases, backups, and file storage are encrypted at rest with AES-256 keys managed by our cloud provider.
Row-level isolation
Every project, brief, and file is scoped to your agency at the database layer with Postgres row-level security. Your data is never queryable from another agency's account.
Least-privilege auth
Roles are owner / admin / member. Long-lived API keys live only on the server. Client-facing keys are publishable-only and cannot read other agencies' data.
Backups & recovery
Point-in-time backups run continuously with 7-day recovery on all plans, extended for Team. Database changes are versioned and reviewed.
GDPR-aligned
Built around GDPR principles: data minimisation, lawful basis per processor, named sub-processors, SCCs for any non-EU transfer, and a Data Processing Agreement available on request.
Operational practices
- Mandatory 2FA for all ScopePilot team members with production access
- All third-party integrations vetted, with a documented sub-processor list (see below)
- Secrets stored in a managed vault — never in source code
- Production access is audit-logged
- Dependency vulnerabilities scanned on every deploy
- No customer data is used to train any AI model — your briefs stay yours
- Documented incident response plan with 72-hour breach notification to affected customers and supervisory authorities, per GDPR Art. 33
Your control
You own your data. Export any brief as PDF or DOCX at any time. Delete your account from settings and we permanently remove your data within 30 days, except where retention is required by law.
Sub-processors
ScopePilot uses the following sub-processors to deliver the service. Each is bound by a Data Processing Agreement and, where data leaves the EEA, by Standard Contractual Clauses (Art. 46 GDPR).
| Sub-processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Supabase (EU region) | Database, authentication, file storage | EU (Ireland) | None — data stays in EU |
| Cloudflare | CDN, edge runtime, DDoS protection | Global edge | SCCs + DPA |
| Paddle | Merchant of Record — payments, tax, invoicing | UK / EU / US | SCCs + DPA (Paddle is independent controller for billing data) |
| Resend | Transactional email delivery | EU / US | SCCs + DPA |
| Google (Gemini API) | AI brief & proposal generation | EU endpoint where available, otherwise US | SCCs + DPA; prompts not used for model training |
| Lovable | Hosting platform & deployment | EU / US | SCCs + DPA |
We notify customers via email of material changes to this list at least 30 days before they take effect.
Data Processing Agreement
A GDPR Art. 28 DPA (including SCCs for international transfers) is available for all paying customers. Email hello@scopepilot.ie with your legal entity name and we'll send a counter-signed copy within 2 business days.
Incident response
If a personal-data breach is detected, we notify affected customers and the relevant supervisory authority within 72 hours of becoming aware, per GDPR Art. 33. Customers can subscribe to status alerts from the status page.
Found a vulnerability?
We take responsible disclosure seriously. Email hello@scopepilot.ie and we'll respond within one business day.