Trust / Security & compliance

Security is part of the product, not a checklist we do later.

We run the same systems we build, every day. Our security posture is shaped by carrying the pager on production attribution and voice infrastructure, not by buying a compliance checklist.

01 / Certifications

what we hold today

HELD

SOC 2 Type II

Annual audit. Latest report available under NDA, request via security@obscale.com.

HELD

GDPR

EU data processed in EU regions. DPA available on request. Standard SCCs in place for transfers.

COMPATIBLE

HIPAA

ScaleCall storage paths support HIPAA-compatible deployments. BAA available on request.

TARGET Q4 2026

ISO 27001

Internal controls already mapped against the Annex A framework. Certification in progress.

02 / How we protect data

six controls · owned by named teams

CTL-01

Encryption

TLS 1.3 in transit. AES-256 at rest. Customer keys managed via cloud KMS with rotation enforced.

CTL-02

Access

SSO + SCIM. Role-based access. Production access requires MFA and time-bound elevation. All access is logged.

CTL-03

Audit

Append-only audit log of every privileged action. Customer-visible audit log on the platform surface.

CTL-04

Vulnerability management

Continuous SAST + DAST. External pen-test annually. Critical findings remediated in < 7 days.

CTL-05

Incident response

24/7 on-call rotation. Customer notification within 24 hours of confirmed material incident. Postmortem published.

CTL-06

Data residency

EU and US regions. Pin a customer to a region; data does not cross. Available on enterprise plans.

03 / Threat model · simplified

tenant-aware by design

Customer data is segmented by tenant, in tenant-pinned warehouses, behind a tenant-aware authorization layer.

PII never trains modelsunless scoped & consented per tenant
tenant-pinned isolationdata does not cross customer boundaries
append-only audit logcustomer-visible · exportable

04 / Sub-processors

who we use · where data sits

Sub-processor Purpose Region Data type
AWS Compute, storage, networking eu-central-1 · us-east-1 All
Cloudflare WAF, edge, DDoS Global Request metadata
Snowflake Warehouse (customer-pinned region) EU / US Event + identity
Datadog Telemetry & observability EU / US Logs, metrics (no PII)
Twilio Telephony for ScaleCall Per region Voice + transcripts
Stripe Billing Global Billing only

Next / responsible disclosure

no legal action against good-faith research

Found something? Tell us. We respond to security reports within four hours during business hours.

security@obscale.com