Security
Built for quiet trust.
This page is maintained by the ScarPath team to describe the security controls that protect your account, your voice, and your reflections.
Encryption
TLS 1.3 in transit. AES-256 at rest. Encrypted database backups with strict key rotation.
Authentication
Modern password hashing, session revocation, and social sign-in with major identity providers.
Secure Storage
Reflections are stored in isolated, access-audited environments with least-privilege access control.
Voice Protection
Voice conversations are streamed over secure channels and are never used to train external AI models.
Private Conversations
Reflection content is scoped to your account only. Row-level security policies enforce isolation at the data layer.
Infrastructure
Hosted on enterprise-grade edge infrastructure with 24/7 monitoring and DDoS mitigation.
Operational Practices
Change management, on-call rotation, and vulnerability response procedures aligned with SOC 2 principles.
Future Compliance Roadmap
SOC 2 Type II and HIPAA-aligned controls are on our roadmap for enterprise availability.
Report a vulnerability
We welcome coordinated disclosure from security researchers. Please email security@scarpath.com with reproducible details. We aim to acknowledge reports within 3 business days.
This page describes practices in effect today and is not, on its own, a certification of compliance with any specific regulatory framework.