Security & trust

What we do with your documents, in plain language

No jargon, no certification badges we haven't earned yet — just what actually happens to your writing.

Encryption in transit and at rest

All traffic is TLS 1.2+. Documents and backups are encrypted at rest with AES-256. Encryption keys are rotated on a fixed schedule, not on request.

Your documents don't train shared models

The AI review pipeline reads a document to generate suggestions for that document. Nothing from a private project is used to train or fine-tune any model, shared or otherwise.

Least-privilege access, logged

Engineer access to production data requires a ticketed reason and expires automatically. Every access event is logged and reviewed monthly.

Exportable, always

Every document exports to standard .tex/.bib at any time, from any plan. Closing your account doesn't hold your writing hostage.

Where we're still working

Honest status on compliance

We're a four-person team. We haven't completed a SOC 2 audit yet — it's scheduled for later this year, and we'd rather tell you that plainly than display a badge we haven't earned. Enterprise customers with specific compliance requirements should talk to us directly before committing; we'll tell you exactly where we stand.

TLS 1.2+ everywhereAES-256 at restSOC 2 audit scheduledGDPR data export on request

Found a security issue?

We don't have a formal bug bounty yet, but we respond to every report personally, usually within a day.

security@scripta.tech