Source
Security page — Scoro
Checked for Scoro on 5 Oct 2026
- Page
- https://www.scoro.com/security
- Checked
- 5 Oct 2026, 04:44 UTC
- How we may use it
- Public page, crawling permitted
Technical details
- type
- page
- http status
- 200
- content hash
- sha256:9981809a3811ba54e0031564551f43f0d058c7f4e0bdd2ee79f04538449338b7
- permission
- robots_ok
- screenshot
- Screenshot on file (internal exhibit, not published)
Cited by
Facts read from this source
-
Provider Report an error
“Scoro software is hosted at various AWS data centers.”
-
Region selection Report an error
“Each client can specify the region where their data is being hosted. By default, the closest to the registration country is chosen.”
-
Backup daily Report an error
“Scoro client sites’ databases and files are backed up daily.”
-
Disaster recovery objectives Report an error
“The Recovery Time Objective (RTO) is 12 hours, and the Recovery Point Objective (RPO) is 24 hours.”
-
Recovery plan testing Report an error
“The data recovery plans are updated and tested annually.”
-
Pen testing Report an error
“The software is pen tested annually based on OWASP Application Security Verification Standard.”
-
Pen testing major releases Report an error
“In the case of major feature releases, additional penetration tests are carried out.”
-
Annual releases Report an error
“In 2024, there were 13 major releases or versions.”
-
Upgrades mandatory Report an error
“All the upgrades are mandatory, i.e. Scoro clients cannot opt out of service pack upgrades.”
-
Maintenance downtime Report an error
“During updates, Scoro services are not available for users. This usually takes 30 seconds, but on rare occasions and for larger sites it may take a bit longer.”
-
Activity log Report an error
“Every action made by users and administrators is logged and visible under Activity Log (as defined in the platform).”
-
Log retention Report an error
“Scoro does not limit the size of the logs. The logs are removed from the system after three years.”
-
API Report an error
“Scoro exposes web services over an API – an interface for accessing clients’ Scoro account data using HTTPS and JSON.”
-
Webhooks Report an error
“All logged events can be sent to the dashboard or to connected systems via webhooks.”
-
File storage Report an error
“Scoro supports File Transfer Protocol (FTP/SFTP), Dropbox, and Google Drive for external file storage.”
-
Import export formats Report an error
“Scoro clients can export data from Scoro to their own solutions by extracting export files in CSV and XLS formats. The same file formats are also supported for data import to Scoro.”
-
Financial and zapier Report an error
“it also acts as a hub integrating external services such as Xero, QuickBooks, and other financial systems, email, reporting suites, and thousands of other applications available through Zapier.”
-
High availability Report an error
“Scoro’s system runs on a high-availability and scalable setup. This means that based on the site’s load more worker instances are created to facilitate the load.”
-
Platforms Report an error
“Scoro can be used with any modern web browser. The system works on all desktop/laptop operating systems (Windows, Macintosh, etc.). Scoro supports the main modern smartphone and tablet operating systems (iOS, Android, etc.), limited to a browser.”
-
ISO 27001 Report an error
“Scoro Software OÜ is ISO 27001 certified.”
-
Two step verification Report an error
“Clients can enable 2-step verification on their site for extra security.”
-
SSO Report an error
“Scoro supports Single Sign-On (SSO).”
-
Https Report an error
“Scoro uses HTTPS encryption protocol for every transaction.”
-
Password encryption Report an error
“Passwords are protected using AES-256 encryption with salts.”
-
Ssl Report an error
“Scoro supports Secure Sockets Layer with 128-bit or stronger encryption for connecting to the application.”
-
Client side caching Report an error
“some of the data is cached client-side. The data is deleted at the client’s session termination.”
-
Payment processor Report an error
“For credit-card-based and other e-commerce transactions executed through Scoro, the transaction security is being assured by Scoro’s trusted partner Stripe.”
-
Stored card data Report an error
“Scoro does not store any information regarding the client’s credit cards except the expiration date and last four digits of the credit card”
-
Tenant isolation Report an error
“All Scoro clients have separate databases and application directories. For larger clients also a dedicated database instance.”
-
Personnel background checks Report an error
“There are internal background checks on personnel with administrative access to servers, applications, and client data.”
-
Vdp Report an error
“Scoro welcomes reports from security researchers and customers to help us keep our product and customers safe.”
-
Vdp contact Report an error
“Email: security@scoro.com (Scoro)”
-
Vdp scope Report an error
“Scoro SaaS application (customer sites hosted on Scoro infrastructure under *.scoro.com) Scoro public API (api.scoro.com) (Scoro) Official Scoro mobile applications (iOS/Android)”
-
Trial Report an error
“Tour the product and try Scoro for free for 14 days, no credit card required.”
-
Data center management Report an error
“The security and availability of each data center are managed by proficient providers and are often verified by us and external partners.”
-
Client side access mediums Report an error
“The platform and its data are accessible through many mediums: web, mobile app, and API.”
-
Backups nightly Report an error
“Backups are made nightly and do not affect user experience.”
Scores citing this record
- The Bootstrapper Pricing transparency
- The Bootstrapper Collaboration depth
- The Bootstrapper Reporting
- The Bootstrapper Integrations
- The Bootstrapper European sovereignty
- The Bootstrapper Support & documentation
- The Bootstrapper Reporting
- The Bootstrapper Integrations
- The Bootstrapper European sovereignty
- The Data Protection Officer Reporting
- The Data Protection Officer Integrations
- The Data Protection Officer Onboarding effort
- The Data Protection Officer European sovereignty
- The Data Protection Officer Reporting
- The Data Protection Officer Integrations
- The Data Protection Officer European sovereignty
- The Enterprise Architect Reporting
- The Enterprise Architect Integrations
- The Enterprise Architect European sovereignty
- The Enterprise Architect Support & documentation
- The Enterprise Architect Reporting
- The Enterprise Architect Integrations
- The Enterprise Architect European sovereignty
- The Integrator Reporting
- The Integrator Integrations
- The Integrator European sovereignty
- The Integrator Support & documentation
- The Integrator Reporting
- The Integrator Integrations
- The Integrator Onboarding effort
- The Integrator European sovereignty
- The Skeptic Collaboration depth
- The Skeptic Reporting
- The Skeptic Integrations
- The Skeptic European sovereignty
- The Skeptic Support & documentation
- The Skeptic Reporting
- The Skeptic Integrations
- The Skeptic European sovereignty
- The Skeptic Support & documentation
- The UX Purist Collaboration depth
- The UX Purist Reporting
- The UX Purist Integrations
- The UX Purist Onboarding effort
- The UX Purist European sovereignty
- The UX Purist Support & documentation
- The UX Purist Reporting
- The UX Purist Integrations
- The UX Purist European sovereignty