Trust Center
How we protect your data
ScaleQuality reads your repositories to measure code maturity, and your engineering metadata (commits, pull requests, boards) to measure delivery. This page explains what we do with your source code, what we keep, what we never collect, and where our own limits are.
01Principles
Anti-surveillance by design
Metrics are team-aggregated, never per-author. We don't collect AI prompt content, nor track keystrokes. No engineer is exposed.
Multi-tenant isolation
Every query carries a mandatory orgId. No silent cross-tenant fallback — verified by automated checks in CI.
Data residency
All data lives in us-east-1 (AWS) today. Regional deployment (EU, Brazil) is scoped as part of an Enterprise engagement, not a switch we flip.
Least privilege
OAuth tokens for your integrations (GitHub, Jira, Azure) use the smallest scope required. No keys are shared across services.
02Compliance and frameworks
We are pre-certification and we say so plainly. What is below is what we can evidence today, plus what we commit to on an Enterprise engagement. DPA requests, sub-processor lists and security questionnaires are answered within 5 business days.
SOC 2 Type II
Not certified yet. We operate against the Trust Services Criteria (access control, change management, encryption, logging) and we start the formal audit as a contracted commitment when an Enterprise customer requires the report.
LGPD (Brazil)
We act as Data Processor (Art. 5, LGPD). DPA available upon request.
GDPR (EU)
SCC addendum available for EU customers. Data subject requests are handled by the security contact below.
We run our own product against ourselves
Every ScaleQuality service is measured by ScaleQuality on every change: static analysis, secret scanning, known-vulnerable dependencies, infrastructure misconfiguration and container CVEs, with a build gate that fails below the line. That is not a substitute for an independent penetration test, and we commission one as part of an Enterprise engagement. It is, however, evidence you can ask us to show, dated, for any commit.
03What happens to your source code
This is the question every security review asks first, so it gets its own section and the plainest words we have.
04How we handle your data
05Sub-processors
Providers that process data on our behalf. Changes to this list are notified to Enterprise customers 30 days in advance.
| Provider | Purpose | Region |
|---|---|---|
| Amazon Web Services | Hosting, database and storage | us-east-1 |
| Amazon Bedrock (Anthropic models) | AI inference for the verdict narrative and for the agents that write code | us-east-1 |
| Stripe | Payment processing | Global |
| Amazon SES | Transactional email delivery | us-east-1 |
| Cloudflare | CDN and DDoS protection | Global |
06AI telemetry connectors
When an organization connects a provider to bring in real usage and billing telemetry, the key is encrypted at rest with AES-256-GCM. No endpoint returns the secret in any response. These are the exact scopes each connector uses.
Anthropic (Claude / Claude Code)
Reads org-wide input/output tokens + cost via the Admin Usage Report API.
Scope read
Admin key (read-only, org-wide)
Cursor
Reads team members, 30-day spend and per-event tokens via the Cursor Team Admin API.
Scope read
Team admin API key
Key encrypted at rest AES-256-GCM with a random IV per value. Auth tag validates integrity. Never appears in any API response or log. Supports rotation, disconnect and test-connection without ever exposing the secret.
Security team
Found a vulnerability? Questions about our threat model? Need a DPA, SCCs, or a filled-out security questionnaire? Reach out — we reply within 1 business day.
Last reviewed: August 9, 2026