Security Practices
Effective Date: November 10, 2025 | Last Updated: July 11, 2026
Data Protection
ScribeosAI implements industry-standard security measures to protect your data.
Encryption
- All data is encrypted in transit using TLS 1.2+
- All data at rest is encrypted using AES-256, provided by our Google Cloud infrastructure
- Authentication credentials are securely hashed by Firebase Authentication
- Application secrets and API keys are stored in Google Cloud Secret Manager; data-at-rest encryption keys are managed by Google Cloud
Infrastructure Security
- Hosted on Google Cloud Platform, a SOC 2 Type II certified infrastructure provider
- All data is processed and stored exclusively in GCP's us-central1 region (Council Bluffs, Iowa, USA) — no offshore storage, no cross-border data transfer
- Google's regular security patches and updates
- Google Cloud network segmentation and firewall protection
- Google Cloud intrusion detection systems
- Google Cloud DDoS protection
- Google Cloud vulnerability scanning
Access Controls
- Role-based access control (RBAC) enforcing strict tenant data separation — no customer can access another customer's data
- Tenant isolation is enforced at the database and file-storage rules layer, not only in the application
- Principle of least privilege for all application access
- Access revocation for removed users
- Access logging for security monitoring
Application Security
- Security-focused code development practices
- Input validation to prevent injection attacks
- Firebase Authentication for secure user management
- Rate limiting for login attempts
- Regular dependency updates and security patches
- Complete audit trails of all document changes and processing operations
QuickBooks Integration
- Connection uses OAuth 2.0 — we never receive or store your QuickBooks password under any circumstance
- Access and refresh tokens are encrypted at rest and stored securely in Google Cloud Secret Manager
- Minimal scopes requested based on the functionality needed
- No permanent storage of QuickBooks data beyond what's required for functionality
- Compliance with Intuit's developer security requirements
Third-Party Sub-Processors
We use a small number of vetted providers, each handling only the data necessary for its function:
- Google Cloud Platform / Firebase — hosting, storage, authentication, and processing (United States, us-central1)
- Stripe — payment processing (PCI DSS Level 1 certified provider)
Data Handling and Retention
- We collect only the data necessary to provide the service
- Data is strictly segregated by tenant
- Data is stored on Google Cloud's redundant infrastructure across multiple availability zones
- Because ScribeosAI processes financial records, we retain your documents and processed data for as long as your account is active, and for any additional period required by applicable law and professional recordkeeping obligations
- For questions about how your data is handled, or to make a specific request, contact privacy@scribeosai.com
- Certain data may be retained as required by applicable law
Certifications & Compliance
- ScribeosAI is built on Google Cloud Platform, whose infrastructure maintains SOC 2 Type II and ISO 27001 certification. We inherit the security and compliance controls of that certified infrastructure and apply the additional protections described on this page.
- GLBA Safeguards Rule: Our administrative, technical, and physical safeguards are designed to be consistent with the Gramm-Leach-Bliley Act's requirements for protecting nonpublic personal financial information — supporting your firm's own compliance obligations.
- PCI DSS: All payment processing is handled by Stripe, a PCI DSS Level 1 certified provider. ScribeosAI never stores full card details.
- Intuit Developer Requirements: Our QuickBooks integration complies with Intuit's developer security guidelines, including OAuth 2.0, minimal permission scopes, and audit logging.
- Regular internal security reviews
- Security assessments for third-party integrations
What We Will Never Do
- Sell or share your client data with third parties for any commercial purpose
- Use your documents or extracted data to train AI models
- Store your QuickBooks password under any circumstance
- Transfer your data outside United States jurisdiction
- Allow cross-tenant data access — your workspace is isolated from all other customers, enforced at the rules layer
Incident Response
- Documented incident response plan with detection, containment, assessment, and notification protocols
- Post-incident analysis and remediation for security events
For breach notification commitments, see our Terms of Service.
For questions about these Security Practices, contact security@scribeosai.com