ScarPath uses industry-standard security controls:
- TLS 1.2+ encryption in transit for all traffic.
- AES-256 encryption at rest for reflections and voice recordings.
- Role-based access control on internal tooling and audit logging of privileged actions.
- Least-privilege database policies (Postgres row-level security) so each user can only read their own data.
- Payment card information is handled exclusively by Stripe and never touches ScarPath servers.
Responsible disclosure
Found a vulnerability? Please email security@scarpath.com. We will acknowledge within two business days.