Trust
Secure by design
ScanOps follows security best practices for a multi-tenant SaaS platform. We do not claim SOC 2 or ISO certification unless and until an independent audit is completed and published.
What we implement today
- Organization-scoped data isolation — each workspace owns its QR codes, scans, and inventory records.
- Role-based access control (owner, member, viewer) with billing and branding restricted to owners.
- Session-authenticated API routes; service-role keys never exposed to browsers.
- Scan IP addresses hashed with a server-side pepper — not stored in plain text.
- Bot verification on signup and sensitive auth flows (Turnstile when configured).
- Billing grace period preserves live QR redirects — customer-facing links are never ad-hijacked.
- Health monitoring at /status and /health — no fabricated uptime percentages.
Compliance roadmap
Enterprise customers may request a security questionnaire or DPA. Formal SOC 2 Type II or ISO 27001 certification will be announced only after completion — not before.
Questions? Contact us or review our Privacy Policy.