Scoped

Where your data lives, and who can touch it.

A plain account of how Scoped keeps your business records: where they are stored, who can reach them, what a connected assistant can do, and how you leave with all of it.

Drawn from the privacy policy effective September 23, 2026.

Where records live

Scoped Cloud is hosted by Amazon Web Services in the United States (Northern Virginia), on a managed PostgreSQL database. Automated database backups are kept for 14 days. Scoped Connect, the desktop app, keeps records on a database you control instead; see Scoped Connect for availability.

Safeguards

Scoped uses access controls, hashed passwords, encrypted two-factor secrets, session revocation, HTTPS, and encrypted database storage. You can sign in with a passkey, or with Google, Microsoft, or Slack, and add two-factor authentication. These are safeguards, not a promise of perfect security or end-to-end encryption; the privacy policy says so in the same words.

Who in your business can see what

  • Every member of a workspace can see that workspace’s records. Work that must stay separate belongs in its own workspace.
  • Client guest access is not included: customers do not get logins to your workspace.
  • Workspace owners and administrators manage membership and roles; the admin role comes with Pro.

Connected assistants

  • You connect an assistant yourself, to one workspace at a time, and approve its permissions on a consent screen before it can do anything.
  • Scoped checks the grant, your membership, the workspace, and the permission again on every request. A read-only connection cannot write, whatever it is asked.
  • The assistant never receives database credentials; it works through Scoped’s application interface.
  • Revoke a connection at any time. Future access stops at once; what was already recorded stays in the history.
  • Scoped does not run your AI. The assistant runs in its own tool, and anything it retrieves may be processed by its model provider.

The technical detail is in Scoped and MCP and how agent updates work.

Every change is recorded

Customers, deals, and jobs keep a dated activity history. A change that arrives from a connected assistant records the person who authorized the connection and the connection it came through, so nothing lands anonymously and every update can be reviewed.

Taking it with you

Workspace owners and administrators can export supported workspace records whenever they want them; verify a restore before you count on a backup. Finished work is archived rather than deleted. How deletion works, and how long copies remain in backups, is in the privacy policy. See also data, export, and self-hosting.

Report a problem

If you think you have found a security issue, write to support@scoped.ai with what you saw and how to reproduce it. For your own account, the account access guide covers recovery and sessions.