Skip to main content

Security

Controls, not claims

Scorafy is designed for organisations that need controlled, reviewable AI assessment. This page describes the security controls that exist today - and is equally plain about what we do not yet certify.

Tenant isolation on every table

Every table in the database carries row-level security. Your organisation's data is scoped to your organisation at the database layer itself - not just in application code - so a bug in an application query cannot return another tenant's rows.

Human sign-off before results release

Respondents see nothing - no score, no report, no PDF - until an assessor releases their result. The release is stamped with who released it and when, and the action is written to an audit log.

Server-side access control

Multi-factor authentication is available on every account, and once a factor is enrolled the code prompt is enforced on the server - navigating around the browser prompt does not work. Owners and admins can require multi-factor authentication for the whole organisation, in which case a member without it is held at setup and the API refuses their session until they enrol. Five organisation roles gate what each team member can do. Platform administration is a separate, fail-closed role: every read is audited and personal data is masked behind an audited reveal.

Prompt-injection hardening

Everything a respondent submits - answers, uploaded document text, audio transcripts - is wrapped in escaped sentinel markers before it reaches the AI, so instructions hidden inside submitted content are treated as data, not commands.

Data residency: EU and Australia

Scorafy runs two isolated production environments - Dublin (EU) for scorafy.com and Sydney for au.scorafy.com. In each, the database, file storage and the application servers that handle requests run in the same region. Australian-residency customers' assessment data stays in Australia under a signed residency term.

Configurable retention, enforced by the system

Respondent personal data can be retained for a period you choose per assessment - from 30 days to a year - enforced by scheduled jobs that clear free-text answers, transcripts and report narrative, with media deletable at submission. Retention runs are logged. Owners and admins can also permanently delete a single response, or an assessment with all its responses, reports and files, at any time. Video and audio responses can be switched off for the whole organisation, and recordings sent for transcription are opted out of the transcription provider's model-improvement programme.

Respondent requests handled in the product

Owners and admins can export one respondent's data as JSON - their answers, report, scores and override history, nothing from anyone else - and can anonymise that respondent on the spot, which clears their name, email, written and spoken answers, files and report narrative while keeping scores. Both actions are recorded in the audit log.

Encrypted backups, tested restores

Both regions are backed up nightly. Each backup is encrypted before it leaves the backup job, kept for 30 days, and then deleted. Restores are tested by decrypting a real backup into a scratch database and checking row counts against production.

Transparent AI pipeline

Every AI evaluation records the model used, the tokens consumed, and the evidence behind each judgement. Assessors can override any score, and the current model is named on our AI transparency page.

Server-enforced assessment sequencing

In an assessor-paced live sitting, the content of a question that has not been opened is never sent to a candidate's browser, and the server refuses an answer to an unopened question. Where an assessment withholds a score pending sign-off, the score is withheld server-side and kept out of the AI's written prose as well - so it cannot be recovered from the network response or inferred from the wording.

Segregation of duties

Building an assessment and releasing its results are separable across your team's roles, so the same person need not do both. Every release records the individual who made it, and overrides are stored beside the original AI score rather than replacing it.

Evidence chain you can export

Any assessment can be exported as an audit pack - a PDF and JSON pair carrying the model and configuration versions in force at evaluation time, the full override ledger, and the release chain. A reviewer can read it without an account, which is the point: the evidence should not live only inside the tool being questioned.

Documented data processing

Our GDPR page names every subprocessor with its region and role, our DPA is published, and both commit to 72-hour breach notification. Encryption in transit (TLS) and at rest is provided by our infrastructure subprocessors; webhook signing secrets are additionally encrypted by the application (AES-256-GCM). The organisation audit log is append-only at the database layer, and exports of respondent data are recorded in it.

What we do not claim

A security page you can trust has to be honest about its gaps. As at September 2026:

  • SOC 2 and ISO 27001: not certified. Procurement teams review the controls themselves instead - this page, the published DPA, the named subprocessor list, and direct answers to your security questionnaire.
  • GDPR is not a certification and we do not describe ourselves as "GDPR certified". Our GDPR page describes the actual controls and every subprocessor.
  • Single sign-on (SAML with Okta, Microsoft Entra ID or Google Workspace): available on request.

Reviewing Scorafy for procurement?

The detail lives on our compliance pages, and we answer security questionnaires directly. Report a vulnerability or ask anything at adam@scorafy.com.