Compliance Center

Compliance & Security Documentation

This page provides transparency into ScaleDesk360™'s security posture, data privacy practices, infrastructure standards, and government procurement readiness for municipal, state, and federal agencies.

Last Updated: March 15, 2026  | Version: 2.0

Status Legend

CompliantPartialIn ProgressNot YetN/A

Important Notice for Government Procurement Officers

ScaleDesk360™ is a commercial SaaS platform currently pursuing FedRAMP Moderate authorization and SAM.gov registration. It is not yet authorized for use on federal systems that require FedRAMP authorization. State and municipal agencies with less restrictive requirements may proceed under their own risk assessment frameworks. Contact our enterprise team for a full security package including VPAT, SOC 2 report, and penetration test results.

Security Framework

RequirementStatusDetails
HTTPS / TLS 1.3CompliantAll data in transit encrypted via TLS 1.3. HTTP automatically redirected to HTTPS.
HTTP Security HeadersCompliantHelmet.js enforces CSP, HSTS (1 year + preload), X-Frame-Options: DENY, X-Content-Type-Options, Referrer-Policy.
Rate LimitingCompliant120 req/15 min general; 10 req/15 min auth; 30 req/15 min AI endpoints.
Input ValidationCompliantAll API inputs validated via Zod schemas server-side. SQL injection prevented via Drizzle ORM parameterized queries.
AuthenticationCompliantJWT-based session tokens (HS256), 1-year expiry, HttpOnly + Secure + SameSite=Strict cookies.
FedRAMP AuthorizationIn ProgressNot yet authorized. FedRAMP Moderate authorization process has not been initiated. Required for federal use.
FIPS 140-2 EncryptionIn ProgressStandard TLS/JWT encryption used. FIPS 140-2 validated cryptographic modules not yet confirmed.

Data Privacy

RequirementStatusDetails
GDPR (EU/EEA)CompliantData processing agreements available. Right to access, rectification, erasure, and portability supported. DPA available upon request.
CCPA (California)CompliantNo sale of personal information. California residents may request access or deletion. Opt-out mechanism available.
Data ResidencyPartialPrimary data stored on US-based servers. AI inference may route through third-party APIs. Data residency SLA available for enterprise contracts.
Data RetentionCompliantAccount data deleted within 90 days of termination. Audit logs retained for 7 years per IRS guidance.
PII MinimizationCompliantOnly business-necessary PII collected. No SSN, passport, or financial account numbers stored.
HIPAAN/AScaleDesk360 is a marketing automation platform. It is not designed to store, process, or transmit Protected Health Information (PHI). Not suitable for covered entities without a BAA.

Infrastructure

RequirementStatusDetails
Uptime SLACompliant99.5% monthly uptime target. Status page available at /status. Incident notifications via email.
Backup & RecoveryCompliantDaily automated database backups with 30-day retention. Point-in-time recovery available.
Penetration TestingIn ProgressAnnual third-party penetration testing scheduled. Last test: not yet completed (platform launched 2026).
SOC 2 Type IIIn ProgressSOC 2 Type II audit initiated. Expected completion Q4 2026. SOC 2 Type I report available upon request.
ISO 27001In ProgressInformation security management system (ISMS) aligned with ISO 27001 controls. Formal certification in progress.
Disaster RecoveryCompliantRTO: 4 hours. RPO: 24 hours. Multi-region failover capability available for enterprise contracts.

Government Procurement

RequirementStatusDetails
SAM.gov RegistrationIn ProgressSystem for Award Management (SAM.gov) registration in process. Required for federal contract awards.
DUNS / UEI NumberIn ProgressUnique Entity Identifier (UEI) registration pending. Required for federal procurement.
GSA ScheduleNot YetGSA Multiple Award Schedule (MAS) application not yet submitted. Contact sales for sole-source justification support.
FAR CompliancePartialTerms of Service include FAR-compatible clauses for data rights and IP. Full FAR Part 12 compliance review in progress.
ITAR / EARCompliantPlatform does not handle controlled defense articles or export-controlled technical data. Not subject to ITAR/EAR restrictions.
Buy American ActCompliantPlatform developed and hosted in the United States. Qualifies as a U.S.-origin service.

Accessibility

RequirementStatusDetails
Section 508PartialSubstantially compliant with Section 508 Subparts B and C. Full VPAT available upon request. See /accessibility for details.
WCAG 2.1 Level ACompliantAll Level A success criteria met. Semantic HTML, keyboard navigation, and ARIA labels implemented.
WCAG 2.1 Level AAPartialPartially compliant. Known gaps in chart text alternatives and video captions. Remediation scheduled Q2-Q3 2026.
ADA Title IIIPartialWeb content substantially accessible. Ongoing remediation per DOJ guidance on web accessibility.

Available Documentation

The following documents are available upon request for government procurement review. Please email our compliance team with your agency name and intended use case.

VPAT / Accessibility Conformance Report (ACR)Available
SOC 2 Type I Report (2026)Available
Penetration Test Executive SummaryIn Progress
Data Processing Agreement (DPA)Available
Business Associate Agreement (BAA)In Progress
System Security Plan (SSP)In Progress
Privacy Impact Assessment (PIA)Available
Incident Response PlanAvailable

Compliance Contact

Security & Compliance

[email protected]

Response within 2 business days

Government & Enterprise Sales

[email protected]

Sole-source justification support available