Trust Center
How Just Scope IT approaches security, privacy, resilience, and responsible platform operations for MSP customers.
Last updated: July 27, 2026
Security Posture Summary
- CurrentAuthenticated application access, role-based permissions, tenant-scoped records, and audit visibility for key workflow and administrative actions.
- CurrentEncrypted browser/API transport through HTTPS-capable public routing, Cloudflare protections where configured, and Cloudflare Turnstile on the public contact form.
- CurrentStored integration credentials are encrypted where implemented, including Autotask/Egnyte-style sensitive settings.
- In ProgressFormal SOC 2-ready policies, routine external penetration testing, formal restore-test cadence, and CSA STAR Level 1 self-assessment preparation.
Data Handling and Ownership
Customers retain ownership of their submitted business content. Just Scope IT processes customer content and platform records to provide the service, support customers, improve workflows, protect the platform, investigate issues, and maintain auditability. Just Scope IT does not sell customer data.
See the Data Handling and Retention Summary, Privacy Policy, and Terms of Service for more detail.
Platform Operations
Infrastructure and Hosting
Just Scope IT is designed to run as a hosted SaaS application with tenant-scoped application data, public HTTPS access, and administrative access restricted to authorized operators. IONOS is the intended production VPS hosting provider once the production migration is complete.
Authentication and Access
The application uses authenticated sessions, role-based access, tenant-scoped API queries, superadmin guardrails, and audit logging for high-impact administrative and workflow activity.
Logging and Monitoring
Operational logs, workflow audit records, approval events, MCP usage records, and admin actions support troubleshooting, investigation, and reliability review.
Backups and Restore
Backup and restore procedures are being formalized into a documented schedule with restore-test evidence, retention expectations, and protected administrative access.
Security Programs
Customer Shared Responsibility
Customers remain responsible for managing their own users, enforcing least privilege, protecting devices and credentials, configuring integrations appropriately, reviewing generated outputs, and validating SOW/contract/pricing content before relying on it with clients.
More Information
See our Security Addendum, Privacy Policy, Terms of Service, Fair Use Policy, and Subprocessors for details.