Security FAQs

Get quick answers to common security questions about Scrunch. For full details, policies, and real‑time status, visit the publicly accessible Scrunch Trust Center.

Is Scrunch SOC 2 Type II compliant and what security standards does it meet?

Yes. Scrunch has completed a SOC 2 Type II audit by an independent third‑party auditor. Our controls cover infrastructure, product security, internal procedures, and data privacy. You can verify current status, review policies, and see subprocessors in the Trust Center.

Read the full answer: Is Scrunch SOC 2 Type II compliant and what security standards does it meet?

What user roles and permissions are available in Scrunch?

Scrunch supports four roles: Admin, Editor, Viewer, and Guest (agency accounts only). Organization‑wide roles can be customized per brand for granular control, so users can have different permissions across different brands within the same account.

Read the full answer: What user roles and permissions are available in Scrunch?

What single sign-on (SSO) providers does Scrunch support?

Enterprise plans support SSO with Okta, Microsoft Entra ID (formerly Azure AD), and Google Workspace—plus any SAML 2.0 or OIDC‑compliant provider. Configuration options include just‑in‑time provisioning, domain enforcement, admin role management, and brand‑level access controls. For implementation steps, see the SSO setup guide.

Read the full answer: What single sign-on (SSO) providers does Scrunch support?

Does Scrunch collect personal information from people using AI platforms like ChatGPT?

No. Scrunch does not collect personal information from members of the general public. We collect AI responses (including citations and search results) from consumer AI platforms through integrations, partnerships, and APIs, but we do not collect or expose third‑party consumer interactions.

Read the full answer: Does Scrunch collect personal information from people using AI platforms like ChatGPT?