Workspace isolation
Every server read and write is scoped to the selected workspace so one organization cannot access another organization's records.
SECURITY BY DEFAULT
Every server read and write is scoped to the selected workspace so one organization cannot access another organization's records.
Clerk handles production authentication while Scopearo enforces Owner, Admin, Manager, Finance, Member, and Viewer permissions on the server.
Traffic uses HTTPS, secrets remain in encrypted runtime storage, and signed webhooks verify external events before they are processed.
Uploads are validated and limited by plan. Client portal links are tokenized, expire automatically, and can be rotated immediately.
Important workspace changes create durable audit records. Operational backups and health checks support recovery and incident investigation.
Paddle acts as merchant of record and processes payment-card details. Scopearo stores only the subscription identifiers and status needed for access.
Our policies explain what data is processed, which service providers are involved, and how to request access, correction, or deletion. Read the Privacy Policy or contact Scopearo with a security or privacy question.
CLIENT WORK, MOVING FORWARD