Security is foundational to how ScaleDesk Technology builds and operates LeadForGrow™, ScaleDesk HRM™, and enterprise client engagements. We design systems with confidentiality, integrity, and availability in mind — from architecture decisions to day-to-day operations.
Our security commitment
We maintain administrative, technical, and physical safeguards appropriate to the nature of the data we process. Our approach aligns with industry frameworks and enterprise expectations, including practices commonly associated with SOC 2, ISO 27001, and GDPR requirements.
Infrastructure security
- Cloud infrastructure hosted with leading providers using hardened configurations.
- Network segmentation, firewalls, and intrusion detection where applicable.
- Encryption in transit (TLS 1.2+) for data transmitted over public networks.
- Regular patching and vulnerability management for operating systems and dependencies.
- Automated backups and disaster recovery planning for critical systems.
Application security
- Secure coding standards and peer review for production changes.
- Authentication controls including multi-factor authentication for administrative access.
- Role-based access control (RBAC) and principle of least privilege.
- Input validation, output encoding, and protection against common web vulnerabilities.
- Dependency scanning and remediation for known CVEs.
Data protection
- Encryption at rest for sensitive data stores where supported.
- Data classification and handling procedures for client and employee information.
- Logical separation of customer environments in multi-tenant products.
- Secure deletion and retention policies aligned with contractual obligations.
Access management
Access to production systems is restricted to authorized personnel with a business need. We log administrative actions, review access periodically, and revoke credentials promptly upon role changes or offboarding.
Incident response
ScaleDesk maintains incident response procedures covering detection, containment, investigation, remediation, and notification. Where contractual or legal obligations require, affected customers will be notified without undue delay.
Compliance and audits
We design controls to support customer compliance requirements and enterprise procurement processes. Formal audit reports or security questionnaires may be available to customers under NDA as engagements require.
Vendor and subprocessor security
Third-party vendors with access to data undergo security evaluation. Contracts include confidentiality, data protection, and breach notification provisions consistent with our standards.
Report a security vulnerability
If you believe you have discovered a security vulnerability in ScaleDesk products or infrastructure, please report it responsibly to security@scaledesktechnology.com. Include sufficient detail to reproduce the issue. We ask that you do not publicly disclose vulnerabilities until we have had reasonable time to investigate and remediate.
Contact
Security questions: security@scaledesktechnology.com
General inquiries: contact@scaledesktechnology.com