SOC2C

Scope Health security & compliance

An overview of Scope Health's security posture — compliance, penetration testing, subprocessors, and data handling — verified on SOC2C (Listed).

SOC 2 statusSOC 2 Type II · Listed
FrameworksSOC 2 Type II
Penetration testNot listed
Subprocessors1 listed
HostingAWS
Trust centerView

Security questions about Scope Health

Is Scope Health secure?
Security isn't a single yes/no, but Scope Health is SOC 2 Type II compliant, and undergoes third-party penetration testing. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Scope Health have a bug bounty or vulnerability disclosure program?
Scope Health hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@tavahealth.com or via a /security page (Scope Health lists a security contact).
Who are Scope Health's subprocessors?
Scope Health lists 1 subprocessor on its trust center, including AWS. Buyers use this for fourth-party risk review.
Where does Scope Health host or store data?
Scope Health hosts on AWS, and handles Employee personally identifiable information, Credit card information, Personal health information. Data residency details are on its trust center.
Where is Scope Health's trust center or security page?
Scope Health's trust center is at https://security.tavahealth.com. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.

See Scope Health's full SOC 2 profile →