Navigation menu

Security and data protection

For IT, procurement and research offices. State as of 27 September 2026.

How Scraiber hosts, protects and processes your data, and what is not in place today. The binding terms are in our data processing agreement.

Hosting and data location

  • Scraiber runs on Amazon Web Services in the United States (us-east-1, N. Virginia): database, document storage, cache and application servers.
  • Backup copies of stored files are kept in AWS London and Singapore.
  • The web front ends are served by Vercel (United States) behind Cloudflare.
  • Data is processed on AWS in the United States today. EU data residency is available on request for organisations: contact [email protected].

Encryption

  • In transit: TLS from the browser through Cloudflare to our load balancers.
  • At rest: the database is encrypted with an AWS-managed key; file storage and cache use AWS default encryption.
  • Customer-managed keys are not offered.

Sign-in and access

  • Members sign in with email and password, with Google, or with an ORCID iD linked to an existing account. Sign-in is handled by AWS Cognito.
  • Organisations have two roles, administrator and member. Only administrators manage members, billing and organisation settings.
  • Documents are shared through groups with read, write, admin and owner rights. There is no per-document sharing link.
  • Administrators cannot read documents in a member's own groups. Documents in organisation-owned groups are controlled by the organisation's administrators.
  • All customers share one database. Access to organisation data is enforced by the application.

AI and model training

  • Your documents are not used to train Scraiber's shared autocompletion models. Those are trained only on public preprints (arXiv, bioRxiv, medRxiv, chemRxiv, SSRN) held in a separate database.
  • When a member uses an AI feature, the content that feature needs goes to the provider of the model the member selected (OpenAI, Anthropic, Google or Fireworks AI): the prompt, the selected text and, for a journal rewrite, the whole document. Providers process it under their API terms.
  • OpenAI requests are sent with response storage switched off. There is no zero-data-retention agreement with any provider.
  • Autocompletion runs on servers Scraiber operates at AWS and is not sent to a model provider.
  • Personal autocompletion learns from a member's own typed text and is served only to that member. It is on by default and can be switched off in account settings. Deleting the account removes the collected text.

Backups, deletion and incidents

  • Database: continuous backups kept for 35 days and automated backups kept for 21 days. Stored files: daily snapshots kept for 35 days, copied to London and Singapore.
  • Deleting a document removes the document and its stored file. Deleting an account removes the account, its stored files, its personal model data and its payment customer record.
  • At the end of the contract the customer can export its data, and Scraiber deletes the personal data within 30 days. Backups are overwritten on their normal rotation, within 35 days.
  • We notify the customer within 48 hours after becoming aware of a personal data breach affecting its data.

Vulnerability management

  • Every backend container image is scanned with Trivy in continuous integration. A critical finding blocks the build.
  • Infrastructure code is scanned with Trivy on every change.
  • Front-end dependencies are updated through Dependabot.

Data processing agreement and sub-processors

Our data processing agreement under Article 28 GDPR takes effect with the Terms of Use, no signature required. It lists every sub-processor with its purpose and location. Read the data processing agreement

  • Core infrastructure: Amazon Web Services, Cloudflare, Vercel and Stripe.
  • AI model providers, used only when a member triggers an AI feature: OpenAI, Anthropic, Google (Gemini) and Fireworks AI. Mathpix converts formula images to LaTeX.
  • Scholarly lookups receive search queries, not documents: OpenAlex, Crossref, arXiv and the European Patent Office.
  • Transfers outside the EEA are covered by the European Commission's Standard Contractual Clauses.
  • Changes to the sub-processor list are announced to organisation administrators 30 days in advance, with a right to object.

A countersigned copy can be requested in writing from [email protected]

Not in place today

We say so plainly and do not promise dates:

  • Single sign-on (SAML), SCIM or directory sync
  • Multi-factor authentication for Scraiber accounts
  • ISO 27001, SOC 2 or any other certification of Scraiber (our hosting provider AWS holds ISO 27001 and SOC 2 reports)
  • A penetration test or third-party security assessment
  • Zero-data-retention agreements with AI providers
  • Customer-managed encryption keys or a separate database per customer
  • A contractual availability figure (SLA)

Contact

Security and privacy questions: [email protected]
Contractual notices under the data processing agreement: [email protected]

Accessibility of our websites: accessibility statement