Security Measures
Scout Solutions takes the protection of the information entrusted to
us seriously, and applies administrative, technical, and physical
safeguards that are reasonable and appropriate to the nature of the
services we provide and the sensitivity of the data involved. These
measures may evolve as our tools and the threat landscape change, and we
maintain a level of protection that does not materially decrease over
time.
Our approach
- Access. We limit access to systems and client data
to those who need it for their work, and we use authentication and
credential-management practices appropriate to the risk. - Data protection. We protect data in transit using
current encryption standards, and we rely on reputable platforms whose
safeguards include encryption for data they store. We collect and retain
only what we need, and we return or delete client data in line with our
agreements. - Devices and endpoints. Devices used to access
client data are expected to use protections appropriate to the risk,
such as encryption, access controls, and up-to-date software. - Vendors and platforms. We deliver services using
established third-party platforms and consider their security practices
as part of using them. Data that resides in a client’s own systems
remains subject to the client’s controls; we operate within the access
the client grants. - Incident handling. If we become aware of a security
incident affecting client data, we act to investigate and contain it and
notify affected clients without undue delay, consistent with our
agreements. - People and governance. Our team members are bound
by confidentiality obligations, and we review access and practices from
time to time.
Working with your
requirements
For engagements with specific security or compliance requirements, we
are glad to review your security questionnaire and align on the
appropriate measures in our agreement and, where applicable, a data
processing addendum.
Contact
Security questions or to report a concern:
security@scoutsolutions.com
