Security approach

Trust must be engineered before automation scales.

ScaleVane is being designed around tenant isolation, least privilege, secure integrations, human publishing approval, auditability, and transparent data controls.

ScaleVane is currently in development. This page describes planned controls and does not claim independent certification or completed compliance audits.
01

Workspace isolation

Product data will be scoped to authenticated workspaces with server-side authorisation and database-level controls.

02

Least-privilege access

Internal services, integrations, and team roles will receive only the minimum permissions required.

03

Human publishing approval

Connected accounts will not be used for silent publishing. Approval status will be explicit and auditable.

04

Secure OAuth and secrets

Platform tokens and application secrets will be stored outside source code using managed secrets and encrypted transport.

05

Activity and cost logs

AI usage, publishing events, failures, approvals, and sensitive changes will be recorded for investigation and control.

06

Deletion and revocation

Users will be able to disconnect platforms and request deletion of account and product data.

Responsible disclosure

Security concerns may be reported to founder@scalevane.online. Please include enough information to reproduce the issue and avoid accessing, changing, or exposing data that does not belong to you.

Current certifications

ScaleVane does not currently claim SOC 2, ISO 27001, PCI DSS, HIPAA, or other third-party certification. Any future certification status will be published only after completion and verification.