Subscope is not just secure. It enhances your company's security

Read-only access to your mail, Google SSO instead of passwords, AI that asks before it acts. Audited by third parties so you don’t have to take our word for it.

CASA Tier 3 certified
SOC 2 Type I in progress
GDPR
CCPA
Read-only Gmail scope

Subscope reads your company’s invoices to find the software you pay for. That is exactly why we built it to see as little as possible — and to prove it to auditors, not just promise it to you.

Our approach

Every security decision in Subscope starts from one question: what is the minimum we need to touch to do the job? The answer shaped the product. We ask Google for the read-only Gmail scope and nothing more. We search mailboxes for billing patterns instead of crawling them. We keep invoices and drop everything else on the spot.

The same logic applies to people. Subscope recognises corporate software — tools your company pays for or signs into with a work account — and stays blind to everything else an employee does online. Access is tied to Google Workspace identity, so there are no passwords to manage and offboarding happens where it already happens: in your directory.

We also decided early that AI should never be the one pressing the irreversible button. Subscope AI extracts, groups and recommends; a human confirms cancellations, revocations and plan changes.

And because “trust us” is not a security control, we put ourselves through Google’s CASA Tier 3 assessment with TAC Security and are now completing a SOC 2 Type I audit. Below is what that covers — and what it doesn’t.

Compliance at a glance

Audited by third parties, not just promised by us.

Subscope reads invoices from company mailboxes, so we hold ourselves to the strictest bar Google sets for apps that touch Gmail data — and we keep going from there.

Certified

CASA Tier 3

Google’s highest assurance level for apps using restricted Gmail scopes. Independently assessed by TAC Security, including penetration testing, against the OWASP ASVS standard.

Audit in progress

SOC 2 Type I

Independent attestation of our security, availability and confidentiality controls. Type I audit underway; Type II observation period follows.

Compliant

GDPR & UK GDPR

You stay the data controller; Subscope acts as processor under a Data Processing Agreement. EU hosting by default, deletion on request.

Compliant

CCPA

California Consumer Privacy Act requirements met for US customers, including access and deletion rights and no sale of personal data.

Data handling

What Subscope does. What Subscope does not.

Trust is easier when the boundaries are explicit. Here is exactly where we operate — and where we never go.

Subscope does

Encrypt everything

TLS for every connection, encryption at rest for stored data and invoice files. OAuth tokens live in a dedicated secrets vault with rotating keys — never in plain text.

Authenticate with Google SSO

Sign in with your Google Workspace identity. No passwords to create, store or leak. Admin roles mirror your Workspace directory.

Read mail as read-only

We request the narrowest Gmail scope that exists: gmail.readonly. Subscope can never send, modify, label or delete a single email.

Offer data residency options

Customer data is hosted in Germany (EU) by default. US hosting is available on request for companies with US residency requirements.

Track corporate software

We detect the tools your company pays for and signs into — from invoices, Google sign-in authorisations and the Subscope Chrome extension.

Ask before acting

Subscope AI prepares actions for you, but always asks for confirmation before anything irreversible — cancelling, removing access, or changing a plan.

Subscope does not

Train AI on your data

Your invoices, emails and usage data are never used to train our models, and our AI providers are contractually prohibited from training on them too.

Read your whole inbox

We query mailboxes with targeted invoice and receipt patterns. Everything that is not a bill is discarded on the spot and never stored.

Track where employees browse

Subscope only sees corporate software. No personal sites, no browsing history, no keystrokes, no screenshots — nothing outside your company’s stack.

Write to your mailbox or apps

Read-only means read-only. Subscope has no permission to send email, change settings or touch anything in your Google Workspace.

Share data across customers

Every company is isolated in its own tenant. Your data is never visible to, or mixed with, another customer’s.

Act without you

No silent cancellations, no automatic revocations. Every irreversible step waits for a human to press the button.

Less uncertainty

You can’t secure software you don’t know exists.

Most SaaS tools show up on an expense report months after the first login. Subscope detects software from three independent signals, so you learn about a new tool the week it appears — not at renewal.

Signal 01

Invoices & receipts

AI reads billing emails in connected mailboxes and extracts vendor, plan, seats and amount — including card payments that never reach procurement.

Signal 02

Google sign-in authorisations

Workspace audit logs reveal every app your team authorises with a company Google account — including free tiers and trials that produce no invoice at all.

Signal 03

Chrome extension

An optional extension confirms which licensed tools are actually in use, so you can spot dormant seats and tools adopted outside the official stack.

The result: no unregistered software.

When a tool appears that isn’t in your approved list, Subscope flags it. You decide whether to approve it, assign an owner, or revoke access before it becomes a risk.

Security controls

Security, layer by layer.

The controls below are the ones verified in our CASA Tier 3 assessment and being attested in our SOC 2 audit. Ask us for the full report under NDA.

01

Application security

  • Verified against OWASP ASVS as part of CASA Tier 3
  • Independent penetration testing by TAC Security
  • Input validation and output encoding on every endpoint
  • Dependency and vulnerability scanning in the release pipeline
02

Data protection

  • TLS in transit, encryption at rest for databases and files
  • OAuth tokens and secrets held in a dedicated secrets vault
  • Encryption keys rotated on a schedule
  • Invoice documents stored encrypted, scoped to your company
03

Access & identity

  • Google Workspace SSO — no passwords stored by Subscope
  • Role-based access: admins and members mirror your directory
  • Least-privilege OAuth scopes, read-only for Gmail
  • Strict per-company tenant isolation
04

Email data handling

  • Targeted invoice queries — no full-mailbox crawling
  • Attachments scanned for malware before processing
  • Sensitive-data (DLP) sanitisation before AI extraction
  • Non-billing emails discarded immediately, never stored
05

AI safety

  • No model training on customer data — ours or our providers’
  • AI providers bound by zero-retention, no-training terms
  • Only the minimum context needed is sent to a model
  • Human confirmation required before irreversible actions
06

Infrastructure & privacy

  • Hosted in ISO 27001-certified data centres in Germany; US region on request
  • Monitoring, logging and alerting across the platform
  • GDPR / UK GDPR / CCPA: DPA, sub-processor list and deletion on request
  • Documented incident response and vendor review process
Security FAQ

Questions your security team will ask.

Can Subscope read all of our email?

No. We use the read-only Gmail scope and search for billing patterns only — invoices, receipts, renewal notices. Anything that isn’t a bill is dropped immediately and never stored. Admins can additionally exclude specific people from scanning.

Does Subscope monitor what employees do online?

No. Subscope only recognises corporate software — tools your company pays for or signs into with a work Google account. It doesn’t see personal sites, browsing history or activity outside your stack.

Is our data used to train AI models?

Never. We don’t train on customer data, and the AI providers we use are bound by terms that prohibit training on it as well. Models receive only the minimum context needed to extract an invoice.

Can the AI cancel a subscription without approval?

No. Subscope AI can draft and prepare actions, but every irreversible step — cancelling, revoking access, changing a plan — requires explicit confirmation from an admin.

Where is our data hosted?

In Germany (EU) by default, in ISO 27001-certified data centres. Companies with US residency requirements can request US hosting.

How do we authenticate? Do you store passwords?

Sign-in is via Google Workspace SSO only. Subscope stores no passwords. Admin and member roles are derived from your Workspace directory, so offboarding a user in Google removes their access.

What happens if we disconnect or leave?

Revoking Subscope in your Google account stops all scanning immediately. Deletion of stored data is available on request under our DPA, and we confirm when it’s complete.

What compliance documentation can you share?

Our CASA Tier 3 letter of validation, the SOC 2 report once issued, our DPA and sub-processor list, and penetration test summaries — available under NDA on request.

Responsible disclosure

Found a vulnerability? Tell us first.

We welcome reports from security researchers and respond to every submission. Please give us reasonable time to fix an issue before public disclosure. Write to security@subscope.ai.

Security review

Need our documentation for a vendor review?

Request our CASA Tier 3 validation, DPA, sub-processor list and pen-test summary. We typically respond within two business days. Contact security@subscope.ai or book a call.

Tired of software chaos?