> ## Documentation Index
> Fetch the complete documentation index at: https://www.scrums.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Security & Compliance

> An overview of how Scrums.com protects client data, manages access, and supports regulatory requirements.

## Overview

Scrums.com applies defence-in-depth security principles to protect client workspaces, delivery data, and engineering assets. Security and compliance controls scale with your subscription tier — with Enterprise providing the full set of features required by regulated industries.

## Security at a glance

| Control                             | Standard | Recommended | Enterprise |
| ----------------------------------- | -------- | ----------- | ---------- |
| Email + password authentication     | ✓        | ✓           | ✓          |
| Two-factor authentication (2FA)     | ✓        | ✓           | ✓          |
| Role-based access control           | Basic    | Full RBAC   | Full RBAC  |
| SSO / SAML 2.0                      | —        | —           | ✓          |
| Audit logs                          | —        | —           | ✓          |
| Data encryption (transit + at rest) | ✓        | ✓           | ✓          |
| Penetration testing                 | —        | —           | ✓          |
| Vendor risk questionnaire           | —        | —           | ✓          |

## Compliance frameworks supported

Scrums.com engineering teams and delivery processes are aligned with the following frameworks on the Enterprise plan:

| Framework     | Applicability                                   |
| ------------- | ----------------------------------------------- |
| SOC 2 Type II | Data security and availability                  |
| ISO 27001     | Information security management                 |
| GDPR          | Data protection for EU/UK data subjects         |
| POPIA         | Data protection for South African data subjects |
| PCI DSS       | Payment card industry data security (advisory)  |

## What's in this section

<CardGroup cols={2}>
  <Card title="Authentication & Access" icon="lock" href="/docs/security/authentication">
    Password, 2FA, SSO/SAML, and session management.
  </Card>

  <Card title="Compliance & Regulatory" icon="shield-check" href="/docs/security/compliance">
    Supported compliance frameworks and audit-ready delivery documentation.
  </Card>

  <Card title="Data Protection & Privacy" icon="database" href="/docs/security/data-protection">
    How Scrums.com handles, protects, and stores client data.
  </Card>

  <Card title="IP Ownership" icon="file-certificate" href="/docs/security/ip-ownership">
    Who owns code and assets created during an engagement.
  </Card>

  <Card title="Legal & Terms" icon="scale-balanced" href="/docs/security/legal">
    MSA, Order Forms, NDAs, and platform terms.
  </Card>
</CardGroup>

## Reporting a security concern

If you identify a potential security vulnerability or incident, contact [security@scrums.com](mailto:security@scrums.com) immediately. Enterprise clients have a dedicated escalation path through their Enablement Team.
