Skip to content

Trust

EightScope Trust Centre

This page summarises who runs EightScope, how customer and scan data are handled, and how to contact us about security.

We do not claim hard Australia-only data residency. Where a detail is still unpublished, it is listed plainly at the end of this page.

Last updated 30 July 2026

1.Who operates EightScope

EightScope is operated in Australia by Heuristic Group Pty Ltd, ABN 37 700 907 080. EightScope is the product trading name.

Day-to-day operator contact for customers is support@eightscope.au.

2.What the product is

EightScope provides external website, DNS, email and infrastructure monitoring. Standard scans cover internet-facing checks on verified domains. They are not a full External Attack Surface Management platform and do not claim CVE mapping, API discovery, login testing or active application exploitation unless those capabilities are explicitly included in a scan type.

3.Support and security contacts

Best-effort response targets (not a contractual SLA): Business within 1 Australian business day; Pro and Starter within 2; Free best-effort only. Full detail is under Availability and support.

Prefer coordinated disclosure. Include steps to reproduce, affected URLs or endpoints, and impact. Do not access other customers' data or disrupt service.

4.Security controls

  • Transport encryption: the product is served over HTTPS in production.
  • Account access: authenticated sessions, optional MFA (authenticator or email), and organisation-scoped API access.
  • Domain authority: monitoring and deeper scans require domain verification before sensitive workflows proceed.
  • Application secrets and database credentials are stored in the hosting environment, not in client-side code.

See the Privacy Policy security section for related commitments.

5.Subprocessors and regions

EightScope uses third-party services to run the product. EightScope does not claim that all information is stored exclusively in Australia. Personal information and scan artefacts may be processed outside Australia by the providers below.

  • Vercel: frontend hosting and edge delivery. Processing may occur in Vercel regions outside Australia.
  • Railway: API application hosting and managed Postgres. Live production region for this stack: US West (California, USA). Railway's published regions do not include Australia; EightScope does not claim Australia-only storage.
  • Stripe: payments and billing. Region: Stripe's processing locations (commonly including the United States).
  • Resend: transactional email (alerts, MFA, support mail). Processing may occur outside Australia.
  • Threat / intel providers: used only where a scan module calls an external intelligence API; see scan methodology for module behaviour.
  • Amazon Web Services (Amazon Bedrock): used only when optional AI-assisted report wording is enabled for an organisation and a generation request runs. Inference is configured for the Sydney region (ap-southeast-2). This does not mean all EightScope data is stored in Australia.

6.Optional AI-assisted wording

Optional AI-assisted report wording never changes findings, evidence, severity, priority, score or grade. EightScope remains authoritative for those results.

When AI-assisted wording is enabled and a generation runs, processing uses Amazon Bedrock in the Sydney region (ap-southeast-2).

Inputs are allowlisted and sanitised. EightScope does not send the complete scan result, raw evidence, hostnames, email addresses, IP addresses or WHOIS records to the model by design.

Generated output is validated. Output that introduces unsupported claims or structural changes is rejected and is not stored or displayed.

Accepted AI output is stored in a separate database record linked to the scan. Rejected model output is not persisted. Linked AI records are cascade-deleted when the scan or organisation is deleted from the primary database.

AI-assisted wording is optional and off by default. Opening a saved report or downloading a PDF reads stored ready output only and does not call the model again.

There is currently no customer self-service control in the dashboard to turn AI-assisted wording on or off. Operators control availability with a global feature flag and organisation allowlist.

More detail: Methodology, Privacy Policy, and the FAQ.

7.Scan data and retention

We store account details, verified domains, scan results (including findings, evidence snippets and scores), monitoring settings, alert history and remediation ticket state needed to operate the service.

Published retention schedules:

  • Domain and scan records: kept while the account is active; deleted from the primary database when you delete the domain or account (backups up to 30 days).
  • Security and quota logs: up to 12 months.
  • Account-deletion audit records: up to 24 months.
  • Support / beta / product-quality records: up to 24 months.
  • Billing references: up to 7 years.

Full detail is in the Privacy Policy retention section.

8.Availability and support

EightScope does not currently offer a contractual service-level agreement (SLA) for uptime percentages, recovery times or guaranteed support response times unless a separate written agreement is signed.

Published support targets (best-effort, not an SLA):

  • Business plan: aim to respond to support emails within 1 business day (Australian business days, Sydney time).
  • Pro and Starter: aim to respond within 2 business days.
  • Free: best-effort only; no response-time target.

Support is by email at support@eightscope.au. The service may be interrupted for maintenance, incidents or provider outages.

9.Billing transparency

Paid subscriptions renew automatically at the end of each billing period unless cancelled before renewal. Change-of-mind refunds are generally not provided except where Australian Consumer Law requires otherwise.

Deleting your EightScope account cancels any active paid subscription so it does not renew. Already-processed charges for the current period are not automatically refunded.

Prefer to keep the account and stop renewals instead? Use Manage subscription in Settings to cancel at period end.

10.Incidents

If we become aware of a personal-information breach that is likely to result in serious harm, we will assess and notify affected individuals and the OAIC as required under Australian law. Operational security incidents affecting availability or integrity are investigated and customers are notified when their accounts or scan data are materially affected.

Report suspected incidents to security@eightscope.au.

11.Vulnerability disclosure

A formal vulnerability disclosure policy page is not yet published. Until then, email security@eightscope.au with a clear write-up. We will acknowledge receipt and aim to keep you informed while we investigate.

12.Not yet published

  • Registered office address
  • Hard Australia-only data-residency guarantees (not currently claimed)
  • Formal vulnerability-disclosure policy page
  • Contractual SLA for uptime or support response times