Security & compliance

Built like infrastructure you’d
put in front of your own customers.

ScendCore runs real actions on your behalf, so it’s built for the buyer who has to answer for security. Every action is permissioned, approved where it matters, and written to an audit trail.

Book a live demoRequest our security overview
Shipped

Enforced today.

In production now, not planned, not partial.

Tenant isolation

Row-level security at the database. Your data is walled off and enforced at the data layer, not just the app.

Role-based access control

Granular roles, enforced on every action. People see and do only what their role allows.

Encryption

In transit and at rest.

SSO login

Google and Microsoft OAuth, with resilient fallbacks.

Approvals

Anything high-stakes waits for a human “yes”, with the reason stated in plain English.

Shadow before live

Trial an agent's behavior before it can send anything. You watch it decide before you arm it.

Full audit trail

Every agent action logged: what ran, why, and the outcome. Immutable.

Controlled impersonation

Admin-only, database-verified, revocable, and itself fully audited.

GDPR & UK DPA

Compliance tooling shipped, including data export. CCPA-aligned. Custom DPA available.

Governance

AI acts. You stay in control.

Every capability has an autonomy setting, and two independent gates decide whether an action fires: the Brain’s shadow-vs-live state, and the per-capability policy. The stricter one always wins. Nothing runs unattended that you haven’t armed.

How one action gets cleared
01
Agent proposes
An action is generated with its reason.
02
Policy checked
Role, autonomy level, and spend limits.
03
Gate applied
Shadow or live — the stricter one wins.
04
Human or auto
Sensitive waits for approval; routine runs.
05
Logged
What ran, why, and the outcome.
Suggest

The agent drafts and waits. Nothing sends without you.

Review

The agent does the routine and escalates anything sensitive to a person.

Autopilot

Acts automatically within your ScendCore guardrails — wallet, caps, quiet hours, risk rules, approval policy, kill switch, and plan ceilings still apply. High-risk actions can still require approval.

Autopilot+

Autopilot, plus your custom Policy Engine rules on top of the standard guardrails.

Governance on every action
Autonomy per capabilityShadow before liveApproval routingAudit trailCost controlsSecure & governed
Audit trail

Every action, logged.
Nothing can be edited.

Every action carries the rule that triggered it, the gate it passed, and its outcome, exportable for review.

Audit traillast 24hExport
TimeActionWhy it ranGateOutcome
14:06Follow-up emailDay 4 of sequence, no replyAutonomousSent
13:52Meeting bookedCaller asked for a time, slot freeAutonomousSent
13:47Outreach pausedDeal value above your auto-send limitApprovalAwaiting
13:31Renewal flaggedUsage down 3 weeks runningAutonomousSent
13:18Campaign replyTesting a new cadence before arming itShadowLogged only
Append-only. Entries cannot be edited or deleted, including by admins.
Roadmap

Not yet in place.

We’re deliberate about what we claim. These are in progress:

SOC 2 Type II

We build to SOC 2 principles today. Formal certification is on the roadmap — we are not certified yet, and we will not display a seal until we are.

Enterprise SSO (SAML) and SCIM

Google and Microsoft OAuth login ships today. SAML SSO and SCIM provisioning are planned.

Data residency options (US/EU)

Available for enterprise engagements — confirm scope on the call.

We don’t state a guarantee until its enforcement path is verified. If it isn’t on the list above, it’s already in place.

For enterprise

Built for security-reviewed teams.

Custom DPA, role-based access control, audit export, and a security overview on request. Data residency options (US/EU) available for enterprise — we’ll confirm scope on the call. Sales-assisted onboarding throughout.

Talk to sales

Put it in front of
your security team.

We’ll send the overview and answer the review questionnaire.

Request the security overviewBook a live demo
Security & Compliance — built like infrastructure | ScendCore | ScendCore