We built security into Scaffold from day one — not as an afterthought. Your client data, your leads, and your business information are protected at every layer.
Security Pillars
Every connection to Scaffold — your browser, our servers, and our database — is encrypted over TLS, enforced with no unencrypted fallback. Our database provider encrypts data at rest by default.
Admins control exactly what each user can see and do. Reps only access their own leads. Managers see their team. Owners see everything.
Our servers receive automatic OS-level security patches, and every dependency in our codebase is continuously scanned for known vulnerabilities.
Your data is backed up daily by our managed database provider. Contact us if you need a specific point-in-time restore.
We're a young company and haven't started a formal SOC 2 audit yet. It's on our roadmap as we grow — we'd rather tell you where we actually stand than claim a certification we don't have.
Security researchers can report vulnerabilities directly to our team. We investigate every report and respond within 48 hours.
Our Standards
Passwords are hashed with bcrypt — we never store plaintext credentials
Multi-factor authentication (MFA) available on all accounts
Session tokens expire automatically and are reissued on every refresh
Admin, financial, and record-management actions are logged with timestamps and IP addresses
Dependency vulnerabilities are scanned automatically and flagged for patching
Every tenant's data is isolated at the database query level — no cross-tenant access is possible
Login attempts are rate-limited and accounts lock out after repeated failures
We take every report seriously. Email our security team directly — we'll acknowledge your report within 48 hours and keep you updated on the fix.
hello@scaffoldcrm.com