audit rights dpa residency · Privacy Policy
Scape policy finding
“ Every Sub-processor is bound by DPAs ensuring that Customer Data never leaves the EU, and furthermore AI Sub-processors are bound to strict retention limits: they process Customer Data only to return results, and retain nothing beyond short, time-limited trust and safety windows. Furthermore Scape is certified to SOC 2 Type II and ISO 27001, and our processing of Personal Data complies with the GDPR and relevant Data Protection Laws. We undergo independent third-party audits annually and current certifications and reports are available in the Scape Trust Center. All personnel undergo background checks, sign confidentiality agreements, and complete security training. We run centralized logging, monitoring, and incident-response procedures, and perform regular security reviews and vendor due diligence.”
- Document
- Privacy Policy
- Captured
- 2026-09-25
- Location
- § 13.2 (Organizational security)
- Snapshot SHA-256
- 92a703aee678d73bb963030014cb7e49dc72c0515159b6c9bcbc61c95578b892
Informational only, not legal advice. Terms change; verify the source and capture date.