ScrollStop
HomeFeaturesHow it worksPricingChrome ext.
Free tools
LinkedIn Profile SimulatorPREVIEWLinkedIn Post SimulatorPREVIEWAbout section generatorGENERATORHeadline generatorGENERATORHook generatorGENERATORComment generatorGENERATORProfile auditAUDIT
BlogAbout
Log inGet extension →
HomeFeaturesHow it worksPricingChrome ext.Free toolsBlogAbout
Log inGet extension →
securitytrust · privacy · controls

Security at ScrollStop.

Security and privacy are part of every release. This page summarises how we protect your data, who we work with, and how to reach our security team.

Compliance

SOC 2 Type IIPlanned
On the roadmap. Audit window starts when we cross 50 enterprise customers.
GDPRCompliant
Data Processing Agreement available on request. EU subprocessors only when required.
CCPACompliant
California Consumer Privacy Act compliant.

Security controls

Encryption at rest
All data in Postgres is AES-256 encrypted at rest. BYOK keys are additionally AES-GCM encrypted at the application layer with a key never stored in the database.
Encryption in transit
TLS 1.3 enforced on every endpoint. Strict-Transport-Security with preload.
Authentication
Email + password with strong rules, OAuth (Google, GitHub, LinkedIn), TOTP-based MFA, and WebAuthn passkeys.
Authorisation
Postgres RLS on every table. Permission-string RBAC at the workspace level with custom roles.
Audit logs
Every privileged action is recorded in an account-level audit log (90-day retention, configurable, CSV export).
Backups
Continuous WAL backups with 7-day point-in-time recovery via Supabase.
Vulnerability scanning
Dependabot for dependencies; CodeQL for source. Sentry for runtime monitoring.
Incident response
24-hour acknowledgement; 72-hour notification to affected customers when their data is impacted.

Subprocessors

Third parties that process customer data on our behalf. We notify customers of changes via the changelog.

ProviderPurposeDataLocation
SupabaseDatabase, auth, storageAll app dataus-east-1
VercelApplication hostingRequest logs, build artifactsGlobal edge
StripePaymentsBilling detailsUS, EU
ResendTransactional emailEmail + nameUS
SentryError monitoringStack traces, request contextUS
AnthropicAI processingPrompts (when used)US

Documents

  • Privacy Policy →
  • Terms of Service →
  • Data Processing Agreement →

Report a vulnerability

If you believe you've found a security issue, please email security@scrollstop.ai. We aim to acknowledge within one business day.

Built like a real product.

Encryption at rest, RLS on every table, audit logs by default. The boring stuff, done before you ship - not after the first incident.

Read the privacy policy →Live system status
ScrollStop

The LinkedIn workflow tool built on the 5Cs - Connections, Conversations, Comments, Content, Consistency. For founders, consultants and operators.

in▶@
Product
  • Features
  • How it works
  • Chrome extension
  • Pricing
  • Changelog
Free tools
  • About generator
  • Headline generator
  • Hook generator
  • Comment generator
  • Connection note
  • Profile audit
Resources
  • Blog
  • Help center
  • Roadmap
  • Status
Company
  • About
  • The $47 story
  • Contact
  • Privacy
  • Terms
  • Security
ScrollStop
© 2026 ScrollStop · Built in Melbourne.
v3.0 · LinkedIn workflow toolBuilt by Apptimistic