Your account's security
The first layer of security is your Upscope account.
Create an account for each team member and assign specific permissions
Upscope allows you to invite all your team members or allow them to create an account with their company email address. You can assign each team member specific permissions (e.g. list users, watch user, manage team, manage team settings, manage billing).
Email-only two step log in to prevent password reuse
Password reuse is one of the leading causes of data breaches. We prevent this by requiring your team members to go through a two step log in process where an email with a log in token is sent to their corporate email address.
Remote log out
You can easily log out of other browsers, and as an administrator you can remotely log out other team members of all their sessions.
Evey action your team takes on Upscope (except for screen sharing session details) is recorded and accessible in the admin console. We also record actions taken by Upscope's admin related to your account. Each log item contains a hash of the previous entry to prove no item is changed or removed.
Your connection with Upscope is protected by SSL everywhere. All access cookies are HTTPS only to guarantee no man-in-the-middle can get hold of them.
Your user's security
We only track what you want us to track, and don't save anything we don't need to save.
Ask for user's permission
Transmit data only while screen sharing
Hide sensitive form values
Enable integrity mode
Remote control limited to the browser
Unlike other screen sharing systems where the user has to install software or at a very least an extension, Upscope allows your agents to control the user's browser (limited to clicks and scrolls) with no installs required, making the experience safer and smoother for both agent and user.
All your user's data is only transmitted via secure SSL connections.
Nothing stored, ever
No user content is ever stored on our servers. The only exception are screenshots and assets caching, which are automatically deleted after 30 days and are in any case optional.
Where your data will be kept.
State of the art data centre
Our website is hosted in secure data centers operated by AWS. Our main data centre is in the North Virginia region.
Protected database access
Only key employees are able to access our database (which only holds account information and user metadata in any case). Access is only possible through a secure VPN connection.
Secure by design
We secure your data by avoiding storing it at all. In case of a complete data breach, an attacker would only be able to access your user metadata and your account information. In the remote case an attacker infiltrated our system and managed to deploy an infected version of our app, your user's data would still be secure if you enabled integrity mode.
Our people & location
Created by experts in a secure location
Secure office building
Our office is located in the middle of London and is equipped CCTV and 24/7 security personel and access control.
Only our CTO is able to trigger deployment of the application. No other employee has access to any data.