What runs where, and what we never see.
One page for the person who has to file it: where each part of a review runs, how the data is handled, what the pages load, who else processes data, and how to reach us about a problem. It describes the service as it is today.
On this pageJump to a section
What runs where
A client review has four places. Each holds only what it needs.
| Where | What runs there | What that means |
|---|---|---|
| Your browser | Your signing key, every approval and decision you sign, the instant demo, and every check on the Verify page. | Keys are created in the browser as non-extractable keys and never leave it. Files opened on Verify are not uploaded. |
| ScopeBlind’s service, on Cloudflare | The review record: names, briefs, criteria, decisions, results and a copy of the preview the client saw. The sandbox repository the demo uses. | Stored in Cloudflare D1, KV and R2. The service signs what it observes with its own separate key. |
| Your GitHub repository | The receiver: a workflow you install with one command. It keeps the repository’s write credential and its own signing key, inspects the exact pull request, and applies only a version both people approved. | ScopeBlind never holds your repository credential. A short-lived token limited to that one repository is used only to start the workflow. |
| A model provider | Text, only when someone in a review uses a model feature: a brief readback, a coding job, or Resolve this. | OpenAI for the hosted features; Anthropic or OpenAI for Write assistance. Nothing is sent to a model otherwise. |
ScopeBlind controls only the step it installs in your repository. Anyone else with access to the repository keeps their own permissions, and a preview can change after it is recorded. How it works walks through the loop.
Data handling
- What is stored. The names you type, the public keys of the browsers and agents that take part, the brief and criteria, the decisions and their notes, the results, and a copy of the preview the client saw. For model features, the model’s outputs and token counts, not a separate copy of the prompt.
- What is not. No passwords, because there are no accounts. No private keys. No GitHub tokens. No card details, because there is no checkout. Invitation secrets, pairing codes and tokens are stored only as SHA-256 hashes.
- How long. Retention differs by store and is listed item by item on the Privacy page. Expiry ends access; deletion is by request, by hand, and acknowledged within five business days.
- Trials. The demo and the coding trial run in a disposable repository that ScopeBlind owns. Use fictional information there; anything in a trial should be treated as public.
- No training. ScopeBlind does not train models on your content or on anything else you give it.
Content security policy and third parties
Every page is one self-contained file: its script is inlined and pinned by hash in the content security policy, its fonts are served from scopeblind.com, and the policy forbids everything else. There are no analytics, no tag managers, no tracking pixels, no cookies set by ScopeBlind, and no third-party scripts, fonts, frames or forms. Open the network panel: the only requests are the page, its fonts, and, on the pages that use them, sample files and the policy engine.
| Header | What it does |
|---|---|
Content-Security-Policy | default-src none; scripts allowed only by the hash of this build’s own inline script; fonts, images and connections only from scopeblind.com; no frames, no form posts, no base URI. |
Referrer-Policy | no-referrer: your browser tells no other site where you came from. |
Strict-Transport-Security | HTTPS only, for a year, on every subdomain. |
X-Frame-Options and frame-ancestors | The pages cannot be embedded in another site. |
Permissions-Policy | Camera, microphone, location and payment APIs are turned off. |
Cache-Control: no-transform | The bytes your browser receives are the bytes this build produced; nothing is injected on the way. |
The open verifier
A record does not depend on ScopeBlind to be believed. The formats follow published drafts, and the verifier is open source under Apache-2.0: @veritasacta/verify on npm. The Verify page runs the same checks in your browser without uploading the file. A valid signature establishes that the signed fields are unchanged and which key signed them; it does not establish who holds that key, so pin the keys you rely on through a channel you already trust.
Build integrity
Each release writes a manifest naming every file it produced and the source commit it was built from, and the deploy checks the live site against it. You can read the manifest at /build-provenance.json; the build integrity section explains how to compare it, and the Status page shows which build is live from your own browser.
Sub-processors
The companies that process data for the service, and what each receives. This is the same list as the Privacy page; when one changes, both pages change.
| Company | What for | What it receives |
|---|---|---|
| Cloudflare | Hosting: the site, its functions, the KV store, the D1 database, R2 storage and the preview site | Everything the service stores, and every request, including its IP address and request details. |
| OpenAI | The hosted model features, and Write assistance when OpenAI is the configured provider | The text a model feature sends, only when someone in the task uses one. |
| Anthropic | Write assistance, only when Anthropic is the configured provider | The recent Write conversation, the current readback and the names of your tools. |
| GitHub | Repository connections, starting the receiver and coding workflows, and the demo repository that ScopeBlind owns | The sign-in exchange and repository reads when you connect through GitHub. In a trial, a real pull request in the ScopeBlind demo repository. |
| Resend | Delivering enquiry and feedback emails to our inbox, when email delivery is configured | The contents of the form you sent, including your email address. |
| Google (Workspace) | Our mailbox | Email you send to support@scopeblind.com, and the enquiry and feedback notifications we receive. |
| Your browser’s push service (Google, Mozilla, Apple or Microsoft) | Delivering reminders you turned on | A signed request with an empty body. No task content and no credentials. |
Certifications
We have not completed a SOC 2 report or an external security audit, and we will not claim certifications we do not hold. What we can show today is the open verifier, the published formats, the content security policy on every page, and the build manifest. Compliance mappings from an earlier product are kept under Earlier work and are mappings, not certifications.
Responsible disclosure
If you find a security problem, email support@scopeblind.com with what you found, how to reproduce it, and how to reach you. Please do not test against other people’s reviews or data. We reply to every report, fix what we can, and tell you what we did. The same address is published at /.well-known/security.txt.
The security questionnaire
If your organisation needs a completed questionnaire, a data-flow diagram, or a walkthrough for your team, ask by email and we send it. Nothing on this page is a substitute for your own review of the service against your requirements.