Skip to content

ScopeYes Security

Protecting your projects and approval workflow.

ScopeYes uses focused safeguards for workspace access, private client review links, approval records, and subscription processing.

Google account authentication

ScopeYes uses Google sign-in for workspace access, so the application does not collect or store a separate ScopeYes password.

Authenticated workspaces

Dashboard, project, and change-request management routes require an active authenticated session.

Private approval links

Client review pages use high-entropy private tokens. ScopeYes stores a one-way hash of each token rather than the original token value.

Hosted payment processing

Dodo Payments handles paid checkout and card processing. ScopeYes stores subscription references and status, not complete payment-card details.

Sharing approval links safely

A private approval link works like a bearer link: anyone who has it may be able to view the associated request. Send links only to intended recipients and replace a link if it may have been shared unexpectedly.

What you can do

  • Protect your Google account with strong recovery settings.
  • Keep devices and browsers updated.
  • Do not publish client approval links in public channels.
  • Review project details before sending a request.
  • Report suspected unauthorized access promptly.

Responsible reporting

Report a security concern

If you believe you found a security issue, contact ScopeYes with a clear description and steps to reproduce it. Please do not access, change, or retain other people’s data, and do not perform testing that could disrupt the service.

Email a security report

No internet service can guarantee absolute security. For more detail about information handling, review the Privacy Policy.