Skip to content

Security and trust

Controls designed into the work, stated without inflation

Custom agents, voice calls and marketing accounts all touch sensitive business data. This page separates what ScoChat is built to do from what would require a formal certification to claim.

Tenant isolation Encrypted tokens You approve first

Solution-specific boundaries

What each solution can access, and how that's controlled

Custom AI Employees

Systems only see the data sets a client approves. Integrations are built with least-privilege access to the specific systems in scope, and the security boundaries — what data, what actions, what approvals — are agreed per engagement during discovery.

Voice AI Employee

Call recording, transcription and consent handling depend on the configuration agreed with each client and the law that applies in their jurisdiction. Telephony and business-system integrations are scoped to what the engagement requires, not connected by default.

Marketing by ScoChat

Connected social platforms are accessed only through the API scopes each integration requires. AI-drafted content is a draft: it only enters the publishing calendar after a person previews and schedules it.

General principles

Nine controls the platform enforces

Each one is enforced in the application layer — policies, middleware, repositories and queued jobs — rather than assumed at the edge.

01 Available now

Tenant isolation

Every client-owned record carries organization and workspace scope. Authorization is enforced in policies, middleware, repositories and queued jobs.

02 Available now

Role-based permissions

Viewing, editing, scheduling, publishing, reporting and managing connections are separate permissions.

03 Available now

Encrypted social credentials

Access and refresh tokens remain server-side, encrypted at rest and excluded from normal model serialization and application logs.

04 Available now

Human review before publishing

AI output is a draft. Content only enters the publishing calendar after a person previews and schedules it.

05 Available now

Restricted AI tools

Every tool validates the current user, tenant, schema, risk level and confirmation requirement before it can perform an action.

06 Available now

Audit history

Content changes, publishing attempts, model runs and administrative access are recorded with request context.

07 Available now

Private media delivery

Uploads are validated, scanned and stored in protected object storage rather than exposed through permanent public URLs.

08 Available now

Durable publishing

Queued jobs, distributed locks, stable idempotency keys and provider reconciliation protect against duplicate external actions.

09 Planned

Environment separation

Development, staging and production use separate databases, secrets, storage, social callbacks and AI endpoints.

AI safety

Retrieved content is context — not authority

Documents, web pages and social content are treated as untrusted input. They cannot rewrite the system's rules or silently activate high-risk tools.

Prompt-injection screening

User prompts and retrieved documents are checked for embedded instructions designed to redirect the agent.

Tool risk levels

Read-only search may run automatically; external writes and destructive actions require confirmation or explicit policy.

Structured outputs

Campaigns, actions and analytics narratives must pass a validated schema before the application stores or executes them.

Secret redaction

Credentials and sensitive values are removed before prompts, logs and debugging output.

Operational visibility

Security includes knowing when the system is unhealthy

The production design monitors queue age, failed publishing, call and token errors, model latency and abnormal access patterns.

Connection health

Notify users before avoidable OAuth expiration and surface permissions that no longer work.

Queue and job health

Alert when publishing is delayed, retries spike or a worker stops consuming critical jobs.

AI usage and safety

Track model version, latency, structured-output failures, tool errors and safety blocks.

Access patterns

Watch failed publishing, token refresh errors and abnormal administrative access.

Planned · target architecture

Designed for managed infrastructure and private service access

The planned production architecture uses managed compute, PostgreSQL with pgvector, managed cache and queue services, private storage, key management and a protected edge. This describes the intended target architecture, not a current deployment claim for every solution.

App

Containerized services

Laravel on Azure Container Apps with separate web, worker, scheduler and realtime containers so one workload cannot silently starve another.

Data

Managed data services

PostgreSQL with pgvector for relational and vector data, Azure Managed Redis for queues and cache, and Blob Storage for private media.

Identity

Managed identities

Service identities and Key Vault references are preferred over long-lived credentials embedded in code or container settings.

Edge

Protected ingress

Azure Front Door with web application firewall controls in front of the application, private origins where required, and protected Qwen inference endpoints.

Regional hosting and dedicated environments are agreed as part of a custom engagement, not assumed by default.

Security transparency

ScoChat does not hold SOC 2, ISO 27001 or other formal certification, and parts of the product are under active development. This page describes the controls and architecture we build to and intend for production. Formal certification status will only be published after independent completion.

Certification status

Design controls are not the same as an audit

We would rather tell you the truth during evaluation than defend a claim during procurement.

Do you hold SOC 2 or ISO 27001 certification?

No. ScoChat does not currently hold SOC 2, ISO 27001 or other formal certification, and parts of the product are under active development. This page describes the controls and architecture we build to and intend for production; it is not a certification claim.

Where is data processed?

The intended production deployment uses managed Azure services. Regional hosting and dedicated environments are discussed as part of a custom engagement where relevant.

What happens to Marketing by ScoChat social tokens?

Access and refresh tokens stay server-side, encrypted at rest and excluded from logs. They can be revoked from ScoChat or from the social platform at any time.

How long is data retained?

Retention depends on the solution and is agreed with each client. For custom engagements it is defined during discovery; for Marketing by ScoChat, content and analytics are retained while the workspace is active.

Found something? Send security reports to sales@sconet.com with the subject line “Security”. We acknowledge reports and keep the reporter informed while we investigate.

Next step

Bring your security questionnaire and deployment requirements.

We can walk through data boundaries, AI tool controls, retention and the differences between shared and dedicated environments for your engagement.