Your clients’ data is your business. Here is how we protect it.

Scrambl holds client records, billing and knowledge in one workspace, so access control is the product, not a feature. This page lists only what is true today, and it grows as attestations land.

How is access controlled?

Three independent gates on every surface

Permissions, feature flags and plan entitlement are checked separately on every surface. A person sees a thing only when all three agree, which is what makes one workspace safe to hand to a client.

Client visibility is set per account

Portal visibility is scoped per account and tuned per portal member, with a field level indicator so nobody has to guess what the client can see. Internal notes stay internal unless you decide otherwise.

Publishing is three separate decisions

Internal, per client portal, or public help center are deliberate, independent choices per article. Nothing becomes public as a side effect.

What does the AI get to see, and do?

Benny answers inside your permissions

The assistant is scoped to what the person asking is allowed to see. Answers follow permission settings, so the AI cannot become a side door around access control.

Retrieval is over your workspace, not the open internet

Your articles, notes and recordings are indexed so an answer can cite the paragraph it came from. A wrong answer traces to a source you can fix.

Your content is not training material

Retrieval reads your workspace to answer your questions. Your content is not used to train models.

Usage is visible and budgeted

AI credits are visible and budgeted per organization, so what the AI is doing, and what it costs, is never a surprise.

What happens when something goes wrong?

Every edit is audited

Changes are recorded so you can see who changed what, and when.

Merges leave a tombstone

Merging two records is built to be undone. Under-merging is cheap to fix; over-merging would not be, so it is reversible by design.

Imports and automations keep run histories

Bulk imports and workflow runs are recorded, and a bad import has a route back out. A wrong file is an undo, not an incident.

What the browser extension can and cannot see

Records only while you have it running, on the tab you started it on.

Redaction happens before anything is saved, so credentials and client data do not travel.

Captures land in your workspace under the same three gates as everything else.

Questions security reviewers ask

Who can see a client’s data?

Only people the three gates agree on: permissions, feature flags and plan entitlement are checked independently on every surface. Client-facing visibility is additionally scoped per account and tuned per portal member, with a field level indicator so nobody has to guess what a client can see.

Does the AI train on our content?

No. Retrieval runs over your workspace so answers can cite the paragraph they came from, scoped to what the person asking is permitted to see. Your content answers your questions; it does not become training material.

Can clients see our internal notes?

No, unless you say so. Visibility is set per account and tuned per portal member, and the field level indicator shows exactly what the client sees before they see it.

What does the Capture extension record?

The clicks and screens of the run you start, on the tab you started it on, only while it is running. You edit and redact the draft before anything is published, so credentials and client data do not travel.

Can a mistake be undone?

That is a design rule here. Every edit is audited, merging two records leaves a tombstone so it can be reversed, and imports keep a full run history with a route back out of a bad run.

How do we get your security documentation for a review?

Request it through the contact form and mark it as a security request. It goes to the team directly, and we will work with your reviewer on the questions this page does not yet answer.