Skip to main content

Security

Controls, not claims

Scorafy is designed for organisations that need controlled, reviewable AI assessment. This page describes the security controls that exist today - and is equally plain about what we do not yet certify.

Tenant isolation on every table

Every table in the database carries row-level security. Your organisation's data is scoped to your organisation at the database layer itself - not just in application code - so a bug in an application query cannot return another tenant's rows.

Human sign-off before results release

Respondents see nothing - no score, no report, no PDF - until an assessor releases their result. The release is stamped with who released it and when, and the action is written to an audit log.

Server-side access control

Multi-factor authentication is available on every account, and once a factor is enrolled the code prompt is enforced on the server - navigating around the browser prompt does not work. Five organisation roles gate what each team member can do. Platform administration is a separate, fail-closed role: every read is audited and personal data is masked behind an audited reveal.

Prompt-injection hardening

Everything a respondent submits - answers, uploaded document text, audio transcripts - is wrapped in escaped sentinel markers before it reaches the AI, so instructions hidden inside submitted content are treated as data, not commands.

Data residency: EU and Australia

Scorafy runs two isolated production environments - Dublin (EU) for scorafy.com and Sydney for au.scorafy.com. Australian-residency customers' assessment data stays in Australia under a signed residency term.

Configurable retention, enforced by the system

Respondent personal data can be retained for a period you choose per assessment - from 30 days to a year - enforced by scheduled jobs, with media deletable at submission. Retention runs are logged.

Transparent AI pipeline

Every AI evaluation records the model used, the tokens consumed, and the evidence behind each judgement. Assessors can override any score, and the current model is named on our AI transparency page.

Documented data processing

Our GDPR page names every subprocessor with its region and role, our DPA is published, and both commit to 72-hour breach notification. Encryption in transit (TLS) and at rest is provided by our infrastructure subprocessors.

What we do not claim

A security page you can trust has to be honest about its gaps. As at August 2026:

  • We do not hold SOC 2 or ISO 27001 certification. Scorafy is an early-stage product and we say so - the controls above are real, the certificates are not yet.
  • GDPR is not a certification and we do not describe ourselves as "GDPR certified". Our GDPR page describes the actual controls and every subprocessor.
  • Single sign-on (SSO/SAML) is not yet available.

Reviewing Scorafy for procurement?

The detail lives on our compliance pages, and we answer security questionnaires directly. Report a vulnerability or ask anything at adam@scorafy.com.