Security Addendum
This addendum describes our security posture and shared responsibility model for protecting MSP customer data in the Just Scope IT platform.
Last updated: July 27, 2026
1. Shared Responsibility
Just Scope IT responsibilities
- Secure platform infrastructure and service operations.
- Maintain access controls, logging, and monitoring.
- Apply reasonable patch and vulnerability management practices.
- Maintain incident response procedures.
Customer responsibilities
- Manage user provisioning and least-privilege access.
- Protect endpoint devices and local credentials.
- Validate outputs before using them in client commitments.
- Configure integrations and data retention according to policy.
2. Security Controls
- Role-based access permissions and administrative controls.
- Audit visibility for key workflow actions and approvals.
- Encryption in transit for browser and API traffic.
- Operational logging to support investigation and reliability.
3. Authorized Platform Access
Just Scope IT may access customer environments, records, files, settings, integrations, logs, and usage data when needed for support, troubleshooting, security review, abuse prevention, reliability, research, product improvement, legal compliance, billing, and enforcement. Access is limited to authorized personnel, contractors, subprocessors, automated systems, or administrative tooling with a business purpose.
Just Scope IT will not sell customer data.
4. Incident Response and Notifications
We maintain procedures for triage, containment, remediation, and recovery. Where required by law or contract, we provide notice of confirmed incidents affecting customer data without unreasonable delay.
5. Responsible Disclosure
If you identify a potential vulnerability, please report it to [email protected] with details sufficient for validation and remediation.
6. Safety of Personnel
Just Scope IT maintains a zero-tolerance policy for threats, harassment, or abuse directed at employees, contractors, or support staff. We may suspend interaction channels or accounts where credible safety concerns exist.