Security, privacy and data
How Scriboflow protects your data
Understand the main safeguards Scriboflow uses to protect accounts, contracts and organisation data.
Last updated August 25, 2026
Scriboflow combines account controls, organisation-scoped access and activity records to help protect contract work.
Account protection
Scriboflow supports:
- Email verification
- Password and magic-link sign-in
- Optional multi-factor authentication with an authenticator app
- Organisation membership and role-based access
Only people who belong to an organisation can access its workspace through the application.
Data protection
Scriboflow uses TLS to protect supported network connections. The providers used for the production database and object storage document encryption at rest.
Organisation checks and row-level access controls are designed to keep one organisation's data separate from another. Access to service credentials is restricted according to purpose.
Activity records
Important contract and signing events are recorded to support contract timelines, signing evidence and security investigations. These records can include timestamps, signer activity and IP information.
Security is a shared responsibility. Protect your account credentials, enable multi-factor authentication and regularly review who can access your organisation.
For current details about Scriboflow's safeguards and compliance roadmap, read the Security Overview.