audit rights dpa residency · Privacy Policy
Scenario policy finding
“ Scenario is SOC 2 Type II certified, demonstrating our commitment to maintaining rigorous security controls. Our current SOC 2 Type II audit report is available through our Trust Center at trust.scenario.com. We implement and maintain appropriate technical and organizational measures to protect your personal information, including: Encryption in Transit. All data transmitted between clients and Scenario’s systems is encrypted using TLS 1.2 or higher. Encryption at Rest. Personal data stored by Scenario is encrypted at rest using AES-256 encryption. Access Controls. Role-based access controls limit access to personal data to authorized personnel on a need-to-know basis. Multi-factor authentication is required for administrative and privileged access to production systems. Infrastructure Security. All production systems are hosted on Amazon Web Services (AWS) infrastructure in US regions. AWS data centers maintain ISO 27001, SOC 1, SOC 2 Type II, and SOC 3 certifications. Workspace Isolation. Each customer’s workspace is logically isolated from other customers’ workspaces within the platform. Monitoring and Logging. Access and activity logs are maintained for systems processing personal data. Vulnerability Management. Regular vulnerability scanning and penetration testing of production systems. Incident Response. Documented security incident response and escalation procedures. While we implement industry-standard security measures, no method of transmission over the Internet or method of electronic storage is completely secure. We cannot guarantee absolute security of your data.”
- Document
- Privacy Policy
- Captured
- 2026-06-07
- Location
- § 11 (Security)
- Snapshot SHA-256
- 540c434c19d1238ff175daea25a1dfc62f964a48224085eeb165ef9c0bcd894e
Informational only, not legal advice. Terms change; verify the source and capture date.