EPRScope
TRUST & DATA HANDLING

Security controls without inflated claims.

EPRScope separates the public sample workspace from customer access, scopes customer data by organization and role, and keeps authenticated customer application and API responses out of shared caches.

Last updated: August 12, 2026Public control summaryNo certification claim
Current boundary: this page describes controls implemented in the current application. EPRScope does not claim SOC 2, ISO 27001 or another third-party certification.
Infrastructure

The web application and serverless functions are deployed through Vercel. Application data is stored in Neon Postgres. Production traffic is served over HTTPS with long-duration HSTS enabled.

Tenant isolation

Customer queries and mutations are scoped server-side to the authenticated organization. Role requirements are enforced by the server for privileged customer actions.

Authentication and sessions

Customer access uses time-limited login tokens and host-prefixed, Secure, HttpOnly, SameSite=Strict session cookies. Login and session tokens are stored as hashes rather than reusable plaintext values.

Browser protections

Customer application pages use no-store caching, restricted framing, content-type protection, same-origin referrer handling, limited browser permissions and a Content Security Policy.

Public demo data

The public demo uses fictional companies and sample assessments. It is isolated from customer login and is not intended for customer-confidential documents or compliance decisions.

Analytics and lead data

The public site uses Google Analytics. Access requests may collect name, work email, company, approximate entity count, product interest and attribution as described in the privacy policy.

Retention and requests

Information is retained as reasonably necessary to operate the service, meet legal obligations and protect the platform. Access, correction and deletion requests can be directed to the contact below.

Responsible reporting

Report a suspected security issue privately to greg@aurorumventures.com. Do not include passwords, tokens or sensitive customer records in the initial message.

Evaluate the controls and the operating method together.

Review how monitored sources, retained versions, human review and failure visibility are represented before requesting access.

Read the methodology →Privacy policy