Scrunch logo
Scrunch
Enterprise and security

Scrunch enterprise security: SOC 2, SSO, roles and procurement

A source-checked enterprise review of Scrunch SOC 2 Type II, SAML and OIDC SSO, roles, audit logs, SCIM, data residency, legal terms, and public service status.

Trakkr editorial teamPublished 2026-08-25
9 min read
Last updated: August 25, 2026

Quick answer

Is Scrunch ready for enterprise security review and procurement?

Scrunch has the main evidence many enterprise reviews require: it states SOC 2 Type II completion, provides SAML and OIDC SSO with just-in-time provisioning, documents role-based access and audit logs, and operates a public status page. Its SSO guide says SCIM is not supported. Current public material does not define selectable data residency, audit-log retention or export, or a public DPA path. Buyers should request the gated Trust Center packet and contract-specific answers.

Published by Trakkr. Sources checked 2026-08-25.
Evidence: Scrunch SOC 2 and security standards, Scrunch single sign-on integration, Scrunch user roles and permissions, Scrunch pricing and plan comparison, Scrunch system status, Scrunch Privacy PolicyVerification: partially verified. The security capability is stated, but procurement details for audit-log access are not public.Not publicly verified. A private enterprise arrangement may differ. Buyers with residency requirements should obtain the hosting region and transfer terms in writing.
Certification
Scrunch states SOC 2 Type II completedEvidence: Scrunch SOC 2 and security standards
Enterprise SSO
SAML 2.0 and OIDC with just-in-time provisioningEvidence: Scrunch SOC 2 and security standards, Scrunch single sign-on integration
SCIM
Current official SSO guide says not supportedEvidence: Scrunch SOC 2 and security standards, Scrunch single sign-on integration
Roles
Admin, Editor, Viewer, and agency Guest with brand overridesEvidence: Scrunch user roles and permissions
Data residency
Customer-selectable regional residency is not publicly documentedEvidence: Scrunch Privacy Policy, Scrunch SOC 2 and security standardsNot publicly verified. A private enterprise arrangement may differ. Buyers with residency requirements should obtain the hosting region and transfer terms in writing.

Scrunch enterprise control checklist

Scrunch enterprise control checklist
ControlPublicly documentedOpen procurement detailBuyer action
SOC 2 and privacySOC 2 Type II completion plus GDPR and CCPA alignment claimsAudit and other reports are gated through the Trust CenterRequest the current report, bridge letter, scope, and exceptionsEvidence: Scrunch SOC 2 and security standards
IdentityEnterprise SAML 2.0 or OIDC, domain enforcement, and just-in-time provisioningSCIM is explicitly not supported in the current guideDefine joiner, mover, and leaver steps around JIT and manual deprovisioningEvidence: Scrunch SOC 2 and security standards, Scrunch single sign-on integration
AuthorizationAdmin, Editor, Viewer, and agency Guest roles with brand-level overridesPublic documentation does not describe custom roles or attribute-based policyMap every internal job to the closest standard role before rolloutEvidence: Scrunch user roles and permissions
Audit trailScrunch states comprehensive audit logs are availablePlan gate, event list, retention, and export format are not publicRequire sample events and retention terms for the chosen planEvidence: Scrunch SOC 2 and security standards, Scrunch pricing and plan comparisonVerification: partially verified. The security capability is stated, but procurement details for audit-log access are not public.
Data locationPrivacy policy allows processing and storage in the United States and other countriesNo public customer-selectable residency option was foundPut region, transfers, subprocessors, deletion, and recovery in the security scheduleEvidence: Scrunch Privacy Policy, Scrunch SOC 2 and security standardsNot publicly verified. A private enterprise arrangement may differ. Buyers with residency requirements should obtain the hosting region and transfer terms in writing.
Reliability evidencePublic status separates Application, API, and AI collections and shows incident historyA public status page is not a contractual uptime or support commitmentObtain the applicable SLA, support channel, and escalation pathEvidence: Scrunch system status

Checked 25 August 2026. A published control is evidence for diligence, but the executed agreement, security schedule, and current Trust Center documents govern procurement.

Does Scrunch have SOC 2 Type II, and what can procurement inspect?

Scrunch says it has completed SOC 2 Type II and links buyers to a Trust Center where reports are gated. It also publishes GDPR and CCPA alignment, role-based access, audit logs, and enterprise identity controls.

The practical diligence step is to request the current report, report period, system scope, bridge letter if needed, exceptions, penetration-test summary, and subprocessor list. The public claim alone does not answer those contract-level questions.

Evidence: Scrunch SOC 2 and security standards

What do Scrunch SSO, provisioning, and user offboarding look like?

Enterprise supports SAML 2.0 and OIDC, just-in-time provisioning, and domain enforcement. Scrunch names standard identity-provider patterns and applies account permissions after login.

Its official SSO guide says SCIM is not supported. That means the buyer should document how users are removed, how dormant accounts are found, and whether identity-provider group changes update Scrunch roles automatically.

Evidence: Scrunch SOC 2 and security standards, Scrunch single sign-on integration, Scrunch user roles and permissions

Can Scrunch isolate brands and produce an audit trail?

Scrunch documents Admin, Editor, and Viewer roles, an agency Guest role, and brand-level overrides to an organization role. That supports basic separation across brands and client workspaces.

Scrunch also states that comprehensive audit logs are available, but public pricing and security pages do not define the plan gate, logged events, retention, or export. Ask for a role matrix and a sample audit export.

Evidence: Scrunch user roles and permissions, Scrunch SOC 2 and security standards, Scrunch pricing and plan comparisonVerification: partially verified. The security capability is stated, but procurement details for audit-log access are not public.

What are Scrunch's data residency and contract options?

The public privacy policy permits processing and storage in the United States and other countries. We found no current public statement offering customer-selectable data residency.

Scrunch's public terms say a separate signed agreement can govern instead of the standard terms. Enterprise buyers should use that path to document location, transfers, retention, deletion, incident notice, subprocessors, and any required data-processing terms.

Evidence: Scrunch Privacy Policy, Scrunch SOC 2 and security standards, Scrunch Terms of ServiceNot publicly verified. A private enterprise arrangement may differ. Buyers with residency requirements should obtain the hosting region and transfer terms in writing.

Does Scrunch publish reliability information and an SLA?

Scrunch operates a public status page with separate Application, API, and AI collections components plus incident history. That gives operations teams a public place to check service state.

The page does not itself establish a contractual uptime promise. Procurement should request the applicable SLA, severity definitions, response targets, support hours, maintenance terms, and service-credit process.

Evidence: Scrunch system status, Scrunch Terms of Service

Evidence and method

A vendor-level SOC 2 claim is public

Scrunch states that it has completed SOC 2 Type II and routes report access through a Trust Center, giving security teams a concrete diligence starting point.

Evidence: Scrunch SOC 2 and security standards

Identity support has a clear missing feature

SAML, OIDC, JIT provisioning, and domain enforcement are documented, while SCIM is explicitly absent, so lifecycle planning can address the gap directly.

Evidence: Scrunch SOC 2 and security standards, Scrunch single sign-on integration

Roles operate at organization and brand levels

The published role model includes brand-level overrides, which is material for enterprises and agencies separating access to multiple brands or clients.

Evidence: Scrunch user roles and permissions

Residency remains a written-answer item

The privacy policy permits international processing, but public security material does not describe selectable residency, so buyers should not infer a regional hosting promise.

Evidence: Scrunch Privacy Policy, Scrunch SOC 2 and security standardsNot publicly verified. A private enterprise arrangement may differ. Buyers with residency requirements should obtain the hosting region and transfer terms in writing.

Operational status is publicly segmented

Separate Application, API, and AI collections components help teams distinguish a user-interface issue from data collection or developer-service availability.

Evidence: Scrunch system status

How we checked this page

We checked Scrunch's current security, SSO, role, pricing, privacy, terms, and status material, separated public controls from gated evidence, and compared Trakkr from its current security page.

  1. 1. Mapped certification, identity, authorization, audit, residency, contract, and reliability statements to current first-party sources.
  2. 2. Marked plan details and contract terms as open when the public source names a feature without retention, export, entitlement, or regional scope.
  3. 3. Avoided treating policy language, a status page, or infrastructure controls as a substitute for a signed SLA or vendor-level certification.
  • Limitation: We did not receive Scrunch's gated SOC 2 report, penetration-test material, security questionnaire, DPA, subprocessor list, or negotiated enterprise agreement.
  • Limitation: Legal and security requirements differ by buyer, so this evidence map is not legal advice or a substitute for internal review.

When is Scrunch or Trakkr the stronger enterprise security fit?

Choose Scrunch when vendor-level SOC 2 Type II evidence is a firm procurement gate. Scrunch states it has completed that audit and also documents enterprise SSO, roles, audit logs, and a public service-status view.

Trakkr publishes strong technical controls including TLS 1.3, AES-256, row-level tenant isolation, role-based access, MFA, and regional isolation, but its security page explicitly says Trakkr does not currently hold its own SOC 2 certification.

Evidence: Scrunch SOC 2 and security standards, Scrunch single sign-on integration, Scrunch user roles and permissions, Scrunch pricing and plan comparison, Scrunch system status, Security at TrakkrVerification: partially verified. The security capability is stated, but procurement details for audit-log access are not public.

Scrunch says it has completed SOC 2 Type II and makes reports available through a gated Trust Center. Buyers should request the current report and verify scope and period.

See how AI talks about your brand

Enter your domain to get a free AI visibility report in under 60 seconds.

14-day trialCancel anytime60 second setup