Scenario / Trust

Security at Scenario.

How access and business data are protected.

01 / Scope

Your workspace

Scenario uses the business information you add or connect to answer questions and generate analyses. Connections offered in your workspace depend on the provider and account configuration. Public website examples are illustrative.

02 / Accounts

Account protection

Email accounts require verification. Passwords are hashed, checked against a known-breached-password service, and protected by rate limits. Password resets expire and revoke existing sessions. Google and GitHub sign-in are also available. Sign-in sessions use secure, HTTP-only cookies in production and expire after seven days.

03 / Data

Data and access

Account information is held in a database reached over an encrypted connection. Access to signed-in pages is checked on the server. OAuth tokens are encrypted at rest. The website sends security headers that restrict framing and several browser features.

These controls reduce risk; no internet service can promise absolute security. Our privacy notice explains the personal information used for accounts.

04 / Connections

Connected accounts

Stripe data connections use OAuth tokens encrypted at rest. The Stripe App is configured for read access needed for analysis; it is not designed to initiate charges, refunds or payouts. You can disconnect through Scenario and remove the App in Stripe. Other supported accounting connections appear in the workspace when available.

Paid subscriptions use a separate Stripe Checkout flow. Card details are entered with Stripe, and Scenario receives subscription status through signed webhooks.

05 / Assurance

Independent assessment

We do not claim SOC 2, ISO 27001, Cyber Essentials, a penetration-test pass or any other certification. We will only display an assessment or badge if it has been earned and its scope can be explained.

06 / Reporting

Report a security issue

Email [email protected] with a description of the issue and how to reproduce it. Please avoid accessing other people’s data, disrupting the service or sharing the issue publicly while we investigate. We will acknowledge reports and work with you on a responsible resolution.

Related: Privacy · Terms