Security architecture
Separate raw-file custody from workspace security.
Supported raw files are processed locally in the browser. The platform stores account, audit and minimized compliance records under scoped controls.
Read the DPA security scheduleTwo data boundaries
Local-file processing does not mean the service stores no personal data.
On your device
Supported input files, extracted raw metadata and cleaned output stay in the browser workflow. Open DevTools → Network and confirm no request contains raw file bytes.
In your workspace
Account, subscription, compliance and audit records live on managed infrastructure. Only the canonical minimized evidence projection can be committed after processing.
Technical measures, by layer
Each statement has a defined scope. Provider configuration and external assurance are separate from a source-level control.
Infrastructure
Managed hosting, database and transport.
- Managed storage boundary
- Compliance records use managed-infrastructure storage. The provider register describes the known configuration and the limits of that evidence.
- Transport protection
- HTTPS/TLS protects application transport. The exact negotiated protocol and cipher are not asserted here.
Application
Browser-local processing and scoped field encryption.
- Browser-local file processing
- Supported raw files and extracted metadata stay inside the browser or an approved customer-controlled workflow.
- Application encryption scope
- AES-256-GCM protects explicitly wired integration credentials and selected sensitive fields. It does not cover every compliance record at the application layer.
Access
Authentication and privilege boundaries.
- Privileged-access controls
- Magic-link, step-up, session and device controls are implemented. Universal MFA or privileged-access enforcement is not claimed.
- Organization scope
- For organization-scoped requests, the shared API boundary checks signed-in membership before the handler proceeds. A copied record link does not grant membership.
Audit
Accountable writes and verifiable record links.
- Audit integrity scope
- Canonical audit writes include SHA-256 hash-chain controls. Complete route coverage and retention, legal-hold, backup and restore assurance are not claimed.
Contract schedule
The published DPA sets out the full security measures, including local-file scope, access, transport, audit, monitoring and incident response. An accepted agreement preserves the exact document version and hash in Billing.
Read the full security scheduleAssurance status
ScrubMetadata does not claim SOC 2 or ISO certification or an independent penetration-test opinion. The controls above describe the implementation and contract boundary; they do not determine your legal compliance.
For data location and supplier contract details, review the provider register. For a security issue, use the contact on the trust center.