Security

Built for quiet trust.

This page is maintained by the ScarPath team to describe the security controls that protect your account, your voice, and your reflections.

Encryption

TLS 1.3 in transit. AES-256 at rest. Encrypted database backups with strict key rotation.

Authentication

Modern password hashing, session revocation, and social sign-in with major identity providers.

Secure Storage

Reflections are stored in isolated, access-audited environments with least-privilege access control.

Voice Protection

Voice conversations are streamed over secure channels and are never used to train external AI models.

Private Conversations

Reflection content is scoped to your account only. Row-level security policies enforce isolation at the data layer.

Infrastructure

Hosted on enterprise-grade edge infrastructure with 24/7 monitoring and DDoS mitigation.

Operational Practices

Change management, on-call rotation, and vulnerability response procedures aligned with SOC 2 principles.

Future Compliance Roadmap

SOC 2 Type II and HIPAA-aligned controls are on our roadmap for enterprise availability.

Report a vulnerability

We welcome coordinated disclosure from security researchers. Please email security@scarpath.com with reproducible details. We aim to acknowledge reports within 3 business days.

This page describes practices in effect today and is not, on its own, a certification of compliance with any specific regulatory framework.