SOC2C

Is this your company? Buyers are checking Scribehow here. Claim scribehow.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Scribehow logo

Scribehow

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Scribehow is SOC 2 Type II compliant. Scribehow also holds CCPA, and GDPR.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

While your teams use Scribe to document and share processes, we want you to know your data is 100% protected. Scribe is not just easy and fast — it’s absolutely secure. Information security and privacy are built into Scribe’s growth, mission and vision. Alongside vulnerability scanning, penetration testing, access control, encryption and data privacy measures, Scribe successfully went through a SOC 2 Type II audit. We are tirelessly committed to the protection of your data and your privacy. Scribe’s information security and privacy controls are detailed below.

Compliance & infrastructure

Hosting
AWS

Documents

21

Subprocessors

14
  • A
    Amazon Web Services, Inc. · Services Provision
    United States of America
  • A
    AssemblyAI · Services provision
    United States of America
  • C
    Cloudflare, Inc. · Services provision
    United States of America
  • A
    Anthropic · Services provision
    United States of America
  • H
    Honeycomb · Services provision
    United States of America
  • F
    Flagsmith (Bullet Train Limited) · Services provision
    United States of America
  • W
    WorkOS, Inc. · Services provision
    United States of America
  • S
    Snowflake · Services provision and analytics
    United States of America
  • O
    OpenAI · Services provision
    United States of America
  • S
    Scaleflex SAS (“CloudImage”) · Services provision
    United States of America
  • I
    Idera, Inc. (API Layer) · Services provision
    United States of America
  • S
    Stripe · Billing
    United States of America
Show all 14 subprocessors
  • S
    SendGrid · Product communications
    United States of America
  • P
    Pendo · Analytics
    United States of America

Compliance leadership

The person who leads Scribehow's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Scribehow's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

Axios Supply Chain Attack NoticeMar 2026

We’ve reviewed the recent advisory concerning compromised Axios versions on npm and can confirm that we were not impacted. Scribe does not leverage Axios in our application stack. Scribe services were not exposed to the malicious packages. We will continue to monitor our supply chain as supply chain attacks emerge and can confirm we are not impacted.

Notice Regarding Shai-Hulud 2.0 npm Supply Chain AttackNov 2025

We are aware of the Shai-Hulud 2.0 npm supply chain attack, in which malicious versions of certain open-source packages were published and used to exfiltrate secrets and spread across parts of the npm ecosystem. Following a comprehensive review, we confirmed that Scribe was not impacted by this incident. Our team validated that our code repositories, dependency chains, and build processes are free from the malicious packages associated with this attack. As part of this assessment: - We examined all dependency manifests and verified that none reference the affected packages or versions. - We reviewed system logs and security telemetry and found no indicators of compromise or suspicious activity related to this campaign. We will continue monitoring industry guidance and threat intelligence for any evolving indicators related to Shai-Hulud 2.0 or similar supply chain risks. If new information emerges, we will update this notice promptly in alignment with our incident response procedures.

2025 SOC 2 Type II Audit ConcludedOct 2025

We’re excited to share that Scribe has successfully completed our 2025 SOC 2 Type II audit with zero exceptions. This milestone reflects our ongoing commitment to keeping your data secure and maintaining the highest standards of compliance. You can count on Scribe to continue investing in the trust, transparency, and protection you expect from us every day.

2024 SOC 2 Type II Audit ConcludedNov 2024

Scribe has successfully completed our 2024 SOC 2 Type II audit. This report demonstrates our commitment to the security of our systems and your data. We engaged an independent third party to review evidence of our controls. We received no exceptions on our report, meaning our auditors found that we have successfully implemented controls to achieve our goal of security of our systems and your data. The report is now available for download via the Trust Center.

Scribe AI Security & Privacy Webpage LaunchOct 2024

It is our team's goal to make your information security reviews as seamless as possible through our commitment to transparency with our customers and users. To that end, we've launched our AI Security & Privacy Webpage, where you will find all information relevant to our use of AI, how your data interacts with AI, and what we do to protect your data. https://scribehow.com/legal/ai-security

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Scribehow SOC 2 compliant?
Scribehow is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Scribehow CCPA compliant?
According to Scribehow's public trust center, Scribehow is CCPA compliant. On SOC2C this listing is Listed.
Is Scribehow GDPR compliant?
According to Scribehow's public trust center, Scribehow is GDPR compliant. On SOC2C this listing is Listed.
Is Scribehow SOC 2 Type I or Type II?
Scribehow is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Scribehow's SOC 2 for a vendor risk assessment?
Yes. Scribehow's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.

Business & Industrial peers that completed SOC 2