Scaledesk Technology

Legal

Security

How ScaleDesk Technology protects infrastructure, applications, and customer data across our products and services.

Last updated:

Zero-trust architecture

Identity-verified access, least-privilege permissions, and encrypted communication across systems.

Defense in depth

Layered controls spanning network, application, data, and operational security.

Secure development

Security reviews, dependency management, and testing integrated into our engineering lifecycle.

Incident readiness

Documented response procedures, monitoring, and escalation paths for security events.

Security is foundational to how ScaleDesk Technology builds and operates LeadForGrow™, ScaleDesk HRM™, and enterprise client engagements. We design systems with confidentiality, integrity, and availability in mind — from architecture decisions to day-to-day operations.

Our security commitment

We maintain administrative, technical, and physical safeguards appropriate to the nature of the data we process. Our approach aligns with industry frameworks and enterprise expectations, including practices commonly associated with SOC 2, ISO 27001, and GDPR requirements.


Infrastructure security

  • Cloud infrastructure hosted with leading providers using hardened configurations.
  • Network segmentation, firewalls, and intrusion detection where applicable.
  • Encryption in transit (TLS 1.2+) for data transmitted over public networks.
  • Regular patching and vulnerability management for operating systems and dependencies.
  • Automated backups and disaster recovery planning for critical systems.

Application security

  • Secure coding standards and peer review for production changes.
  • Authentication controls including multi-factor authentication for administrative access.
  • Role-based access control (RBAC) and principle of least privilege.
  • Input validation, output encoding, and protection against common web vulnerabilities.
  • Dependency scanning and remediation for known CVEs.

Data protection

  • Encryption at rest for sensitive data stores where supported.
  • Data classification and handling procedures for client and employee information.
  • Logical separation of customer environments in multi-tenant products.
  • Secure deletion and retention policies aligned with contractual obligations.

Access management

Access to production systems is restricted to authorized personnel with a business need. We log administrative actions, review access periodically, and revoke credentials promptly upon role changes or offboarding.


Incident response

ScaleDesk maintains incident response procedures covering detection, containment, investigation, remediation, and notification. Where contractual or legal obligations require, affected customers will be notified without undue delay.


Compliance and audits

We design controls to support customer compliance requirements and enterprise procurement processes. Formal audit reports or security questionnaires may be available to customers under NDA as engagements require.


Vendor and subprocessor security

Third-party vendors with access to data undergo security evaluation. Contracts include confidentiality, data protection, and breach notification provisions consistent with our standards.


Report a security vulnerability

If you believe you have discovered a security vulnerability in ScaleDesk products or infrastructure, please report it responsibly to security@scaledesktechnology.com. Include sufficient detail to reproduce the issue. We ask that you do not publicly disclose vulnerabilities until we have had reasonable time to investigate and remediate.


Contact

Security questions: security@scaledesktechnology.com

General inquiries: contact@scaledesktechnology.com

Security inquiries

Questions about this document? Our team will respond promptly.

contact@scaledesktechnology.com