Trust & security
Current controls.
Current limits.
Scopebond is an experimental alpha for controlled test use. This page states what is available today, what remains gated, and how to report a security issue.
Scopebond Cloud is not production protection. Hosted onboarding is on a waitlist, billing is disabled, and staging, tenancy, recovery, capacity, and operational gates remain open.
Open-source alpha
The Apache-2.0 gateway and verifier are public for controlled testing. The self-hosted component includes no Scopebond phone-home telemetry.
Cloud waitlist
The stronger multi-user Cloud candidate remains private and undeployed. Do not send customer production data or rely on the current hosted console.
No certification claim
Scopebond has no SOC 2 report, ISO certification, production recovery SLA, or non-removable compliance-retention claim.
What you can verify now
- Source and package boundary. The public repository contains the gateway, policy schema, verifier, SDK, tests, and release metadata. The hosted control plane remains private.
- Deterministic verification. Signed receipts can be checked offline against the published schema and conformance vectors. A gateway countersignature attests what it observed; it does not independently prove an external system changed or certify compliance.
- Fail-closed design. The current candidate tests deny-by-default policy handling, signed intent and approvals, durable stops, bounded evidence ingestion, tenant authorization, and recovery integrity. Passing local and CI tests is not equivalent to a verified production deployment.
- Public issue handling. Non-sensitive defects can be filed in the public repository. Security-sensitive reports should use the private reporting channel below.
Report a security vulnerability
Email [email protected] with “Scopebond security report” in the subject. Include the affected domain, package and version, impact, reproduction steps, and the smallest safe proof needed to understand the issue.
- In scope: scopebond.com, try.scopebond.com, cloud.scopebond.com, the public Scopebond repository, and published
@scopebond/*packages. - Protect people and systems: use local fixtures or the no-external-effect demo; do not access another person’s data, degrade service, social-engineer anyone, or trigger financial or other external business actions.
- Minimize report data: do not email credentials, access tokens, private keys, personal data, or customer content. Redact sensitive values and describe how we can reproduce the condition safely.
- Coordinated disclosure: allow time for investigation and remediation before public disclosure. Scopebond does not currently operate a paid bug-bounty program.
Machine-readable contact details are published at /.well-known/security.txt.
Public-site service providers
This list describes the current public website and waitlist—not a future customer-data processing agreement for Scopebond Cloud.
- Cloudflare: hosts and protects the public website and its waitlist function and receives ordinary HTTP request metadata.
- Resend: delivers waitlist notifications and may retain submitted email, name, and list-membership data.
- PostHog: may collect public-site pageview and interaction analytics when the deployment key is enabled; the script is inert when it is not configured.
- GitHub and npm: publish source, issues, releases, and packages. Their own terms and privacy notices apply when you use those services.
Formal Cloud subprocessors, data-processing terms, retention commitments, residency options, and enterprise assurance material are not yet published. Do not submit confidential or regulated information through the waitlist.