Security & Privacy

How Scopture protects data through its privacy, access-control, infrastructure, and integration-security practices.

Overview

Scopture is built by Ducflair with data security and privacy at its core. This page summarizes how we protect your data. For full details on data collection and processing, see our Privacy Policy.


Data Protection and GDPR

Scopture is designed and operated to comply with applicable General Data Protection Regulation requirements. We process personal data as described in our Privacy Policy and rely on applicable legal bases, including performance of a contract, consent, compliance with legal obligations, and legitimate interests.

Where required, we enter into appropriate data-processing agreements with service providers that process personal data on our behalf.

For information about your rights, including access, correction, erasure, portability, restriction, and objection, see our Privacy Policy.

Enterprise customers requiring a signed Data Processing Addendum can contact us at [email protected].


Infrastructure

Scopture runs on Amazon Web Services (AWS) with data hosted in EU data centers. Key measures include:

  • Encryption – TLS 1.3 in transit, AES-256 at rest;
  • Access controls – Role-based access control (RBAC) for all internal systems;
  • Authentication – Multi-factor authentication (MFA) support;
  • Backups – Encrypted automated backups with redundancy and defined rotation periods;
  • Monitoring – Infrastructure and application monitoring via Grafana Cloud;

Application Security

  • Security patches and dependency updates are applied promptly;
  • Audit logging for data access and modifications is available for enterprise customers;
  • Security and operational logs are retained for defined periods and are not kept indefinitely;
  • Model Context Protocol (MCP) request content is excluded from operational logs by default;
  • Cookieless, privacy-friendly analytics via self-hosted Umami (no personal data collected).

Connected Integrations

Scopture may provide optional integrations that allow compatible third-party applications and assistants to access selected Scopture functionality at the user’s instruction.

Integration access is authenticated and limited to resources available to the connected Scopture account. Scopture MCP tools include metadata indicating whether they read data or may modify or delete content. This metadata supports informed tool use but does not replace Scopture’s authorization and access-control checks.

Scopture processes only the information necessary to perform the requested operation. Users may disconnect an integration through the connected service and, where available, revoke its authorization through Scopture. Revoked credentials are rejected from future requests.

For more information about integration data processing, retention, disconnection, and deletion, see our Privacy Policy.


Data Retention

Scopture applies defined retention periods to account data, project content, backups, MCP operational metadata, security logs, support records, and financial records.

For the exact periods and applicable exceptions, see Section 5 of our Privacy Policy.


Contact

For security or privacy inquiries:

For general legal matters, see our Legal Hub.


Copyright © 2026 Scopture. All rights reserved.