Trust & safety

Security

At Scribify, protecting your personal and business data is our highest priority. We employ defense-in-depth architectural principles, rigorous access controls, and enterprise-grade infrastructure to ensure your information remains safe, reliable, and private.

01

Data protection & encryption

We enforce strict encryption standards across the entire life cycle of your data.

Data in transit

All traffic between your devices and our servers is encrypted using modern TLS 1.3 and TLS 1.2 protocols. Unencrypted connections are automatically rejected.

Data at rest

Customer data stored in our primary databases and storage volumes is protected using industry-standard AES-256 bit encryption.

Key management

Cryptographic keys are stored separately from application data in hardened, dedicated Key Management Systems (KMS) with strict rotation policies.

02

Infrastructure & network defense

Our core systems are built on top of top-tier, globally recognized cloud infrastructure partners.

Certified cloud environments

Our databases and application servers operate within cloud environments that hold independent certifications including SOC 2 Type II, ISO/IEC 27001, and HIPAA compliance capabilities.

DDoS & edge protection

Web and application traffic is routed through distributed edge networks featuring automated Distributed Denial-of-Service (DDoS) mitigation, Web Application Firewalls (WAF), and rate-limiting safeguards.

Network segregation

Production databases sit isolated in private subnetworks behind network firewalls, shielded from direct public internet exposure.

03

Access control & data isolation

We ensure that customer data remains strictly separated and accessible only by authorized identities.

Strict multi-tenant isolation

Data ownership is controlled directly at the database layer using granular, user-level authorization policies. This guarantees that your data is strictly isolated and accessible only to you or authorized members of your organization.

Authentication security

We utilize modern token-based authentication (JWTs) along with industry-standard cryptographic password hashing algorithms. Multi-Factor Authentication (MFA) is supported to add an additional layer of account protection.

Principle of least privilege

Internal staff access to production management tools is governed strictly by the Principle of Least Privilege, requiring strong multi-factor authentication, audit logging, and explicit role permissions.

04

Business continuity & monitoring

We maintain continuous monitoring and resilience strategies to keep your service online and operational.

Automated backups & point-in-time recovery

Production data is backed up automatically with point-in-time recovery capabilities to safeguard against data loss or corruption.

Continuous system health monitoring

We continuously track uptime, error rates, and infrastructure metrics to proactively identify and resolve potential issues before they impact performance.

05

Vulnerability reporting & contact

We welcome the contributions of the security research community to help keep our platform safe. If you believe you have discovered a security vulnerability or have questions about our security practices, please contact us.

Security email scribifyapp@gmail.com
Response time We aim to acknowledge all security disclosures within 24–48 hours