Security
Last updated August 10, 2026 · Contact: admin@scaffle.ai
What we do
- Encryption in transit: every connection uses TLS.
- Encryption at rest: all stored data lives in a managed Postgres database whose storage is encrypted at rest (AES-256). Tool-connection keys get a second layer: encrypted at the application level with a key kept outside the database.
- Tenant isolation: row-level security inside the database itself walls each account off, so one account’s queries cannot reach another’s.
- Log hygiene: your chats, documents, and email content are never written into application logs.
- Prompt-injection defense: everything Scaffle reads on your behalf is fenced and labeled as material to read, never instructions to follow. A real defense, not a perfect one — and one reason every connection stays read-only. More in the principles.
What we don’t have
No SOC 2, no ISO 27001, no HITRUST — Scaffle is an alpha-stage company with a small team, and we’d rather say so than imply otherwise. If something goes wrong with your data, we will tell you what happened and what we did about it.
Who else touches your data
The full list of service providers, by name and job. Each gets only what its job requires, and the privacy policy covers what flows where.
- Vercel — hosts this website.
- Railway — hosts the Scaffle API.
- Supabase — managed Postgres database and authentication.
- OpenRouter — routes model requests to US-serving AI model providers.
- Firecrawl — reads the public web pages you point Scaffle at.
- Resend — sends transactional email.
- hCaptcha — bot detection on the sign-in and signup forms.
- Sentry — error monitoring, configured to exclude personal data.
- Slack — receives the internal new-signup notice (business name, owner name and email).
- Google — optional sign-in, and Gmail when you connect it.
Data is stored and processed in the United States, and model requests route to providers serving from the United States.
HIPAA, plainly
Scaffle does not sign Business Associate Agreements today, and is not a HIPAA-authorized environment for protected health information. A practice can use Scaffle for the operations that never touch patient data — procedures, scheduling policy, payer playbooks, marketing, reviews — and should not connect a mailbox that carries patient information or paste PHI into chat. If that changes, we’ll say so here explicitly; assume nothing in the meantime.
Retention and deletion
We keep what you give us while your account is open. Deleting a memory fact or a screen note removes it from the database on the spot. Closing the account is an email to admin@scaffle.ai today, confirmed within 30 days and usually much sooner.
Found something?
If you’ve found a vulnerability, or anything on this page that doesn’t match what the product does, write to admin@scaffle.ai. A person reads it, and we’d rather hear it from you than find out later.
See also the privacy policy and principles.