Security program
Security
Scroller, Inc. operates Scroller around secure cloud processing, minimal public infrastructure, and limited access to user email data.
Security measures
- HTTPS for public traffic.
- Private databases and queues that are not directly exposed to the public internet.
- Encrypted storage for sensitive OAuth tokens.
- Access controls for production systems.
- Operational logging for security, abuse detection, and reliability, with sensitive provider payloads and token-like values filtered where possible.
- Separation between the public marketing site and API host.
- Short-lived prefetched rich HTML caching for Feed-eligible messages used to improve full-email expansion performance.
Google API security assessment
Scroller completed Google's OAuth verification and required security assessment for its Gmail integration. Scroller also applies provider authorization, minimum-permission, encrypted-token, retention, and deletion controls to Microsoft Graph access.
Report a vulnerability
Email security@scroller.ai. Include enough detail to reproduce the issue. We appreciate responsible disclosure and ask that you avoid accessing or sharing another person's data.