Is this your company? Buyers are checking Scribehow here. Claim scribehow.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Claim free
Scribehow
Sourced from public information. Not yet verified by the company.
Scribehow is SOC 2 Type II compliant. Scribehow also holds CCPA, and GDPR.
About
While your teams use Scribe to document and share processes, we want you to know your data is 100% protected. Scribe is not just easy and fast — it’s absolutely secure. Information security and privacy are built into Scribe’s growth, mission and vision. Alongside vulnerability scanning, penetration testing, access control, encryption and data privacy measures, Scribe successfully went through a SOC 2 Type II audit. We are tirelessly committed to the protection of your data and your privacy. Scribe’s information security and privacy controls are detailed below.
Compliance & infrastructure
Documents
21- Scribe 2025 SOC 2 ReportRequest
- Scribe 2025 Data Redaction Overview.pdfRequest
- Scribe SIG CoreRequest
- Scribe Cryptography (Encryption) PolicyRequest
- Scribe Reference ArchitectureRequest
- Scribe Data Flow DiagramRequest
- Scribe WCAG 2.1 AA VPAT 2025Request
- Scribe General Liability COI 2025Request
- Scribe Management Practices COI 2025Request
- Scribe Cyber Liability COI 2025Request
- Scribe SIG Lite 2025Request
- Scribe Disaster Recovery PlanRequest
- Scribe W9Request
- Workers Comp COI 2025Request
- Scribe TX RAMP CertificateRequest
- Scribe HECVATRequest
- Scribe Optimize Security OverviewRequest
- SOC 2 Type II Bridge Letter 2026Request
- Scribe Disaster Recovery Test ResultsRequest
- Scribe 2025 Penetration TestPublic
Subprocessors
14- AAmazon Web Services, Inc. · Services ProvisionUnited States of America
- AAssemblyAI · Services provisionUnited States of America
- CCloudflare, Inc. · Services provisionUnited States of America
- AAnthropic · Services provisionUnited States of America
- HHoneycomb · Services provisionUnited States of America
- FFlagsmith (Bullet Train Limited) · Services provisionUnited States of America
- WWorkOS, Inc. · Services provisionUnited States of America
- SSnowflake · Services provision and analyticsUnited States of America
- OOpenAI · Services provisionUnited States of America
- SScaleflex SAS (“CloudImage”) · Services provisionUnited States of America
- IIdera, Inc. (API Layer) · Services provisionUnited States of America
- SStripe · BillingUnited States of America
Show all 14 subprocessorsShow fewer
- SSendGrid · Product communicationsUnited States of America
- PPendo · AnalyticsUnited States of America
Compliance leadership
The person who leads Scribehow's SOC 2 isn't listed yet. Claim this profile to add it.
Penetration test
Unknown. Scribehow's penetration test vendor isn't listed yet.
Claim this profile to add it.
Recent updates
Axios Supply Chain Attack NoticeMar 2026
We’ve reviewed the recent advisory concerning compromised Axios versions on npm and can confirm that we were not impacted. Scribe does not leverage Axios in our application stack. Scribe services were not exposed to the malicious packages. We will continue to monitor our supply chain as supply chain attacks emerge and can confirm we are not impacted.
Notice Regarding Shai-Hulud 2.0 npm Supply Chain AttackNov 2025
We are aware of the Shai-Hulud 2.0 npm supply chain attack, in which malicious versions of certain open-source packages were published and used to exfiltrate secrets and spread across parts of the npm ecosystem. Following a comprehensive review, we confirmed that Scribe was not impacted by this incident. Our team validated that our code repositories, dependency chains, and build processes are free from the malicious packages associated with this attack. As part of this assessment: - We examined all dependency manifests and verified that none reference the affected packages or versions. - We reviewed system logs and security telemetry and found no indicators of compromise or suspicious activity related to this campaign. We will continue monitoring industry guidance and threat intelligence for any evolving indicators related to Shai-Hulud 2.0 or similar supply chain risks. If new information emerges, we will update this notice promptly in alignment with our incident response procedures.
2025 SOC 2 Type II Audit ConcludedOct 2025
We’re excited to share that Scribe has successfully completed our 2025 SOC 2 Type II audit with zero exceptions. This milestone reflects our ongoing commitment to keeping your data secure and maintaining the highest standards of compliance. You can count on Scribe to continue investing in the trust, transparency, and protection you expect from us every day.
2024 SOC 2 Type II Audit ConcludedNov 2024
Scribe has successfully completed our 2024 SOC 2 Type II audit. This report demonstrates our commitment to the security of our systems and your data. We engaged an independent third party to review evidence of our controls. We received no exceptions on our report, meaning our auditors found that we have successfully implemented controls to achieve our goal of security of our systems and your data. The report is now available for download via the Trust Center.
Scribe AI Security & Privacy Webpage LaunchOct 2024
It is our team's goal to make your information security reviews as seamless as possible through our commitment to transparency with our customers and users. To that end, we've launched our AI Security & Privacy Webpage, where you will find all information relevant to our use of AI, how your data interacts with AI, and what we do to protect your data. https://scribehow.com/legal/ai-security
This listing is partial
7/11 details · 64%SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
- Auditorraises trustAdd the CPA firm that issued your SOC 2 so buyers can verify who signed it.
- Report dateraises trustAdd your most recent report period so buyers see how current your SOC 2 is.
- Renewal dateAdd your renewal window so buyers know your coverage is active.
- Security controlsConfirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Scribehow SOC 2 compliant?
Is Scribehow CCPA compliant?
Is Scribehow GDPR compliant?
Is Scribehow SOC 2 Type I or Type II?
Can I use Scribehow's SOC 2 for a vendor risk assessment?
Is Scribehow penetration tested?
Can I get Scribehow's SOC 2 report?
Is Scribehow secure?
Does Scribehow have a bug bounty or vulnerability disclosure program?
Who are Scribehow's subprocessors?
Where does Scribehow host or store data?
Where is Scribehow's trust center or security page?
Do you encrypt data at rest?
How do you handle the data we collect?
Do you support Single Sign-On (SSO)?
Where are your servers located?
What privacy/security settings are available?
How do you monitor for security breaches?
How can we minimize the data that we share with Scribe?
Do you use our data to train AI?
Do you share our data with third parties?
What data does Scribe collect?
Does Scribe record videos?
How does Scribe use OpenAI?
Business & Industrial peers that completed SOC 2

Newsworthy.ai

1099-Prep

Octopus Deploy
