Security & Data Protection at Scanara
Every layer of Scanara is built to protect your data, your organization, and your compliance posture.
Data Protection
EU Data Residency
All data is stored and processed exclusively within the EU/EEA — eu-west-1 (Dublin, Ireland) as the primary region, with an encrypted disaster-recovery replica in eu-central-1 (Frankfurt). No data ever leaves the EU/EEA.
Data Protection
End-to-End Encryption
AES-256 encryption at rest for all stored data. TLS 1.2+ for all data in transit. Customer-managed KMS keys for the audit store.
Access Control
Authentication & SSO
OIDC and SAML single sign-on for enterprise teams. Cognito Advanced Security with adaptive authentication and compromised credential detection.
Compliance
Immutable Audit Trail
Every action writes to a WORM-S3 audit log with SHA-256 integrity hashes. 10-year retention aligned with EU AI Act Articles 11 & 12. Ready for regulatory inspection.
Data Privacy
GDPR & Data Privacy
Right to erasure via saga-orchestrated hard delete. Automated per-organization data retention policies. Soft-delete with 30-day grace period and full anonymization support.
Access Control
Role-Based Access Control
Six granular roles from super_admin to viewer. Per-organization membership and least-privilege defaults. No cross-organization access, ever.
Procurement
Evaluating Scanara as a vendor?
Pre-filled security questionnaire, DPA template, sub-processor list, and architecture overview — ready for your procurement team.