Security & Trust
How we protect your data and infrastructure, who we rely on, and how to reach us about security. We believe in being upfront about both what we do today and what we are still building.
Last updated: June 26, 2026
Scanora AI is an early-stage, founder-led operation. We have not yet completed a formal third-party audit such as SOC 2 Type II — we are actively working toward it. The controls described below reflect what we genuinely practice today. We would rather tell you exactly where we are than imply certifications we do not hold.
Our Security Posture
Encryption in Transit
All traffic to our site and the systems we manage is served over HTTPS using modern TLS (1.2+). HSTS is enabled.
Access Control
We use role-based access and the principle of least privilege for client systems, with credentials stored in a dedicated secrets manager — never in plain text.
Backups & Recovery
Managed clients receive automated backups following a 3-2-1 strategy with encrypted off-site copies and a documented, tested restore process.
Monitoring
We monitor availability and security signals for managed services and respond to incidents promptly. See our status page.
Edge Protection
We use Cloudflare for CDN, DNS, TLS, and DDoS/WAF protection in front of the properties we manage.
Working Toward SOC 2
We are building our processes and documentation toward SOC 2 Type II. We are happy to discuss our current controls with you directly.
Data Handling & Residency
- We collect only the data needed to deliver and support our services. See our Privacy Policy for full detail.
- We do not sell or rent personal data to third parties.
- Sensitive data is encrypted in transit and at rest where applicable.
- Data may be processed by our sub-processors (below), which operate across multiple regions. We can discuss specific residency needs for your organization.
- You can request access to, correction of, or deletion of your data at any time by emailing us.
Data Retention & Deletion
- Service-inquiry and audit-lead data is retained for up to 24 months after the last interaction, then deleted.
- Client data tied to an active agreement is retained for the duration of the agreement plus 12 months, then deleted or returned on request.
- Backups follow a 3-2-1 strategy with defined rotation; expired backups are purged on schedule.
- You may request earlier deletion at any time by emailing admin@scanoraai.com; we action verified requests within 30 days.
Incident Response
Our incident-response process for the services we manage:
- Detect — monitoring and security signals flag an anomaly.
- Contain — we isolate the affected system and stop the bleeding.
- Eradicate & recover — remove the cause, patch, and restore from clean backups.
- Notify — affected managed clients are informed directly; material incidents are noted on our status page.
- Review — a post-incident review captures root cause and prevention.
Response-time targets depend on your plan; formal service credits apply only under a signed Enterprise SLA.
Sub-processors
We rely on a small number of reputable providers to operate our business. These may process limited data on our behalf:
| Provider | Purpose |
|---|---|
| Cloudflare | CDN, DNS, TLS, WAF/DDoS protection |
| Managed cloud / cPanel hosting provider | Website and application hosting |
| Razorpay | Payment processing (when you check out) |
| Email delivery provider | Transactional and support email |
This list reflects our current providers and may change as we grow. Material changes will be reflected here.
Data Processing Agreement
Need a DPA for your compliance requirements? We provide one on request for managed clients.
Request a DPA →Responsible Disclosure
Found a security issue? Please report it privately and give us a reasonable window to remediate before any public disclosure.
Report a vulnerability →Talk to Us About Security
For security questions, compliance documentation, or to discuss your requirements: