ScopePilot logo
Security & Trust

We treat your client data like it's our own.

ScopePilot is built for agencies that handle confidential client information every day — pitches, brand strategy, internal numbers. Here's exactly how we keep it safe.

How we protect your data

EU-hosted by default

Your account, briefs, proposals, and uploaded files are stored on EU-region infrastructure. Limited operational data may be processed by EU or US sub-processors under Standard Contractual Clauses — see the list below.

Encrypted in transit & at rest

Every connection uses TLS 1.2+. All databases, backups, and file storage are encrypted at rest with AES-256 keys managed by our cloud provider.

Row-level isolation

Every project, brief, and file is scoped to your agency at the database layer with Postgres row-level security. Your data is never queryable from another agency's account.

Least-privilege auth

Roles are owner / admin / member. Long-lived API keys live only on the server. Client-facing keys are publishable-only and cannot read other agencies' data.

Backups & recovery

Point-in-time backups run continuously with 7-day recovery on all plans, extended for Team. Database changes are versioned and reviewed.

GDPR-aligned

Built around GDPR principles: data minimisation, lawful basis per processor, named sub-processors, SCCs for any non-EU transfer, and a Data Processing Agreement available on request.

Operational practices

Your control

You own your data. Export any brief as PDF or DOCX at any time. Delete your account from settings and we permanently remove your data within 30 days, except where retention is required by law.

Sub-processors

ScopePilot uses the following sub-processors to deliver the service. Each is bound by a Data Processing Agreement and, where data leaves the EEA, by Standard Contractual Clauses (Art. 46 GDPR).

Sub-processorPurposeLocationTransfer mechanism
Supabase (EU region)Database, authentication, file storageEU (Ireland)None — data stays in EU
CloudflareCDN, edge runtime, DDoS protectionGlobal edgeSCCs + DPA
PaddleMerchant of Record — payments, tax, invoicingUK / EU / USSCCs + DPA (Paddle is independent controller for billing data)
ResendTransactional email deliveryEU / USSCCs + DPA
Google (Gemini API)AI brief & proposal generationEU endpoint where available, otherwise USSCCs + DPA; prompts not used for model training
LovableHosting platform & deploymentEU / USSCCs + DPA

We notify customers via email of material changes to this list at least 30 days before they take effect.

Data Processing Agreement

A GDPR Art. 28 DPA (including SCCs for international transfers) is available for all paying customers. Email hello@scopepilot.ie with your legal entity name and we'll send a counter-signed copy within 2 business days.

Incident response

If a personal-data breach is detected, we notify affected customers and the relevant supervisory authority within 72 hours of becoming aware, per GDPR Art. 33. Customers can subscribe to status alerts from the status page.

Found a vulnerability?

We take responsible disclosure seriously. Email hello@scopepilot.ie and we'll respond within one business day.