Trust

Why you can trust Scopebond with your agents

You're handing a product control over what your AI coding agents may do. That deserves plain answers: how we protect you, what our product does and doesn't claim, and who we are.

The principle behind everything we build

Autonomy is earned through accountability.

Authority should be explicit, actions should be verifiable, and failures should be recoverable. That is Avouro's operating principle, and Scopebond is that principle, shipped.

Proof, not badges

Don't trust us — verify

Most security pages ask you to trust a badge. Scopebond is open source and every decision is signed, so you can check the important claims yourself, right now — no account, no call.

A signed record you can check in ten seconds

This is a signed sample Scopebond record for a blocked production-database drop by a coding agent. Your browser verifies the signature live; change one character with Tamper with it on how it works and the check fails. Offline, run npx @scopebond/gateway@latest verify record.json. Where competitors say "certified", we say: here is the evidence.

scopebond:recordsigned
{
  "type": "scopebond:receipt",
  "decision": "deny",
  "reason": "blocked: DROP DATABASE on production (rule prod-db-protected)",
  "action_ref": "sha256:9f2c0b7ad1e4c6f80b3a2d15c7e9f4a1a71b",
  "policy_digest": "sha256:41d0e2a9c7b3f6108d4e5a2c9b0f7e13c88e",
  "issued_at": "2026-09-21T14:14:07Z",
  "issuer_id": "sb_hook",
  "kid": "ed25519:3b9f",
  "executed": false,
  "external_effect": "not_independently_verified"
}
Signed with Ed25519. Verify offline: npx @scopebond/gateway@latest verify record.json

How we protect you

Your rules run in your environment

Enforcement happens on your developers' machines or in your own GitHub runner. We never hold a credential that can act on your systems. Our service holds only signed records.

Records carry no sensitive data

No prompts, no file contents, no personal data. Only identifiers, the rule that decided, and cryptographic fingerprints. Secrets are scrubbed before anything is signed.

Fails safe, and it's open

If anything is unclear, the answer is "no." The hook and gateway are open source under Apache-2.0, so anyone can inspect exactly what they do, and they never phone home.

Proof anyone can check

Records are signed and verify against published keys, offline. Each one says whether Scopebond checked the action before it ran, checked a required boundary such as merge, or only recorded what another platform reported.

Your data, your account

The workspace uses Google, Microsoft or GitHub sign-in; each person keeps individual access; every privileged action is logged. Export or delete your records when you choose.

Where your data is stored

Today every workspace is stored in the United States, on Cloudflare. Regional workspaces are coming: when you create a workspace you will choose the United States or the European Union, and its agents, computers, rules and records stay in that region. Your sign-in, workspace membership and billing link are held centrally in the United States, and service logs may be processed outside the region. A workspace's region can't be changed later.

Mapped to recognized standards

Implemented controls are mapped, narrowly and honestly, to NIST CSF 2.0 and SP 800-53 references, with what's ours and what's yours spelled out. No compliance score, no badges we haven't earned.

Our product, honestly

True today

The open-source hook and gateway enforce real rules, sign real records and have a kill switch. Records verify offline. The live demo at try.scopebond.com makes real decisions with no side effects.

Where we are

Scopebond is in early access. The hook and the GitHub Action enforce your rules on the actions routed through them today, and the workspace is in early access while Team and Business are coming soon. Roll it out to one team or project first, then widen it. Each setup page says what Scopebond checks and what remains outside it; unfinished connections are on the roadmap.

What we won't say

No "100% compliant," "zero risk" or "court-ready." No certifications we don't hold: there is no SOC 2 report and no third-party penetration test yet. A record proves what was requested and decided, never that a business result happened.

This page describes the controls we operate today. It is not a certification, audit report, SLA, legal advice, or contractual security commitment. Contractual terms come with a signed agreement.

What Scopebond can and cannot stop

What it stops

An action that routes through Scopebond and breaks your policy is blocked before it runs: an out-of-policy tool call in Claude Code, Cursor or Codex, an MCP tool call, or an HTTP action sent through the gateway. A coding-agent pull request touching a protected path fails a required GitHub check and cannot merge. A rule blocks only once it is set to Block; on Monitor it records what it would have stopped. Scopebond's own protection is always on: a coding agent cannot change Scopebond's settings or remove it. Every decision, allowed or blocked, is signed into a record you can verify offline.

What it does not stop

The desktop connector checks supported actions sent through its local hook. An agent or process that does not use that hook, or reaches a system Scopebond is not in front of, is outside this check. For pull requests, make the Scopebond GitHub Action a required check. For HTTP or MCP actions that must be checked, put the gateway in front of the tool. A valid record proves what was requested and decided; it does not by itself prove an external effect happened, or that an action was compliant.

Who we are

Scopebond is made by Avouro, a technology company built for responsibility. Avouro studies how to make autonomous and AI systems safe, verifiable and accountable, and turns that research into infrastructure people can actually run: open source where openness makes it more trustworthy, supported where teams need it.

Our operating principle is that human judgment stays in control: authority is declared, not assumed; every action leaves proof; and when trust is misplaced, there is recourse.

Avouro LLC · Michigan, USA · avouro.com · support@scopebond.com

Secure by design

Fail-closed defaults, tamper-evident records, least privilege. First principles, not features.

Human accountable

A named person is responsible for every agent; rule changes are reviewed by a colleague.

Evidence over claims

We publish what's true, what's on the roadmap and what we won't promise, on this page and in the product.

Reporting and disclosure

Report a security issue

Email security@scopebond.com or use the details published at /.well-known/security.txt. We acknowledge every report and coordinate a fix before disclosure. Scopebond does not currently operate a paid bug-bounty program.

Services we rely on

Cloudflare for hosting; Resend for access-request email; PostHog for product analytics. Autocapture is off, no session replay, and no third-party pixels. See PrivacyTerms.

Legal

Nothing on this site is an offer of insurance, securities or financial services, or legal or financial advice. Scopebond is a trademark of Avouro LLC.