Security

How we protect your data

Last updated July 1, 2026.

ScarPath uses industry-standard security controls:

  • TLS 1.2+ encryption in transit for all traffic.
  • AES-256 encryption at rest for reflections and voice recordings.
  • Role-based access control on internal tooling and audit logging of privileged actions.
  • Least-privilege database policies (Postgres row-level security) so each user can only read their own data.
  • Payment card information is handled exclusively by Stripe and never touches ScarPath servers.

Responsible disclosure

Found a vulnerability? Please email security@scarpath.com. We will acknowledge within two business days.