Reviewed product guidance
Security and data handling
Verified transport, access, hosting, storage, and certification disclosures.
Magic-link client portal: availableClient and staff file uploads: certification-pending
Current controls
The public service uses HTTPS, EU-hosted infrastructure, RS256 JWT verification for staff APIs, scoped portal tokens, non-public object storage, and expiring presigned URLs.
Current limits
DocScoop is not SOC 2 certified and does not publish an uptime SLA, independent at-rest encryption certification, or complete subprocessor register. Security reports should go to security@docscoop.com without client documents or credentials.