Trust & security

Current controls.
Current limits.

Scopebond is an experimental alpha for controlled test use. This page states what is available today, what remains gated, and how to report a security issue.

Scopebond Cloud is not production protection. Hosted onboarding is on a waitlist, billing is disabled, and staging, tenancy, recovery, capacity, and operational gates remain open.

Open-source alpha

The Apache-2.0 gateway and verifier are public for controlled testing. The self-hosted component includes no Scopebond phone-home telemetry.

Cloud waitlist

The stronger multi-user Cloud candidate remains private and undeployed. Do not send customer production data or rely on the current hosted console.

No certification claim

Scopebond has no SOC 2 report, ISO certification, production recovery SLA, or non-removable compliance-retention claim.

What you can verify now

Report a security vulnerability

Email [email protected] with “Scopebond security report” in the subject. Include the affected domain, package and version, impact, reproduction steps, and the smallest safe proof needed to understand the issue.

Machine-readable contact details are published at /.well-known/security.txt.

Public-site service providers

This list describes the current public website and waitlist—not a future customer-data processing agreement for Scopebond Cloud.

Formal Cloud subprocessors, data-processing terms, retention commitments, residency options, and enterprise assurance material are not yet published. Do not submit confidential or regulated information through the waitlist.