Scopevra
Public Trust Center

Security claims tied to implemented controls.

This page separates repository-verified controls from provider and independent-assurance work that still requires external evidence.

Identity

OIDC/JWKS token verification, verified-email provisioning and server-authoritative tenant membership.

Tenant isolation

Tenant authorization is backed by PostgreSQL row-level security; adversarial tests cover REST and GraphQL boundaries.

Credentials

API keys are shown once and stored only as digests. Webhook signatures and worker tokens use timing-safe comparison.

Audit

Administrative, billing, agent-decision and entity-merge actions have durable audit or ledger records.

AI boundary

Retrieved source content is untrusted evidence. Human approval does not execute external contact, payment or submission.

Recovery

An isolated restore runbook and verification tool exist. Provider retention and a dated production restore drill require external evidence.

Assurance status

Internal automated testing
Implemented in CI
Internal manual review
Documented; repeat after material changes
Independent penetration testing
Not yet completed
Security certification
None claimed