Security Overview
A practical summary of the controls used to protect Just Scope IT customer environments.
Last updated: July 27, 2026
Current Controls
- CurrentAuthenticated access is required for the application and API.
- CurrentRole-based access controls separate standard users, tenant admins, approvers, and superadmin-only functionality.
- CurrentTenant-scoped API queries and data models help keep customer records separated by tenant.
- CurrentSuperadmin tenant access is guarded and intended for administrative support, with visible impersonation context and audit logging.
- CurrentStored integration secrets are encrypted where implemented, including sensitive Autotask and Egnyte settings.
- CurrentAudit logs, approval logs, MCP usage records, and operational logs support investigation and troubleshooting.
In Progress
- In ProgressFormal written policies for access control, change management, incident response, vulnerability management, backup/restore, and secure development.
- In ProgressRoutine third-party penetration testing and customer-shareable remediation summary.
- In ProgressFormal production restore-test evidence and backup retention documentation.
- In ProgressCSA STAR Level 1 self-assessment preparation and SOC 2 readiness groundwork.
Change Management
Application changes are tracked through source control and build processes. The compliance roadmap formalizes this into a customer-auditable process with documented review, testing, deployment, rollback, and evidence retention.