Scrunch enterprise security: SOC 2, SSO, roles and procurement
A source-checked enterprise review of Scrunch SOC 2 Type II, SAML and OIDC SSO, roles, audit logs, SCIM, data residency, legal terms, and public service status.
Quick answer
Is Scrunch ready for enterprise security review and procurement?
Scrunch has the main evidence many enterprise reviews require: it states SOC 2 Type II completion, provides SAML and OIDC SSO with just-in-time provisioning, documents role-based access and audit logs, and operates a public status page. Its SSO guide says SCIM is not supported. Current public material does not define selectable data residency, audit-log retention or export, or a public DPA path. Buyers should request the gated Trust Center packet and contract-specific answers.
Key facts and evidence
- Certification
- Scrunch states SOC 2 Type II completedEvidence: Scrunch SOC 2 and security standards
- Enterprise SSO
- SAML 2.0 and OIDC with just-in-time provisioningEvidence: Scrunch SOC 2 and security standards, Scrunch single sign-on integration
- SCIM
- Current official SSO guide says not supportedEvidence: Scrunch SOC 2 and security standards, Scrunch single sign-on integration
- Roles
- Admin, Editor, Viewer, and agency Guest with brand overridesEvidence: Scrunch user roles and permissions
- Data residency
- Customer-selectable regional residency is not publicly documentedEvidence: Scrunch Privacy Policy, Scrunch SOC 2 and security standardsNot publicly verified. A private enterprise arrangement may differ. Buyers with residency requirements should obtain the hosting region and transfer terms in writing.
Scrunch enterprise control checklist
| Control | Publicly documented | Open procurement detail | Buyer action |
|---|---|---|---|
| SOC 2 and privacy | SOC 2 Type II completion plus GDPR and CCPA alignment claims | Audit and other reports are gated through the Trust Center | Request the current report, bridge letter, scope, and exceptionsEvidence: Scrunch SOC 2 and security standards |
| Identity | Enterprise SAML 2.0 or OIDC, domain enforcement, and just-in-time provisioning | SCIM is explicitly not supported in the current guide | Define joiner, mover, and leaver steps around JIT and manual deprovisioningEvidence: Scrunch SOC 2 and security standards, Scrunch single sign-on integration |
| Authorization | Admin, Editor, Viewer, and agency Guest roles with brand-level overrides | Public documentation does not describe custom roles or attribute-based policy | Map every internal job to the closest standard role before rolloutEvidence: Scrunch user roles and permissions |
| Audit trail | Scrunch states comprehensive audit logs are available | Plan gate, event list, retention, and export format are not public | Require sample events and retention terms for the chosen planEvidence: Scrunch SOC 2 and security standards, Scrunch pricing and plan comparisonVerification: partially verified. The security capability is stated, but procurement details for audit-log access are not public. |
| Data location | Privacy policy allows processing and storage in the United States and other countries | No public customer-selectable residency option was found | Put region, transfers, subprocessors, deletion, and recovery in the security scheduleEvidence: Scrunch Privacy Policy, Scrunch SOC 2 and security standardsNot publicly verified. A private enterprise arrangement may differ. Buyers with residency requirements should obtain the hosting region and transfer terms in writing. |
| Reliability evidence | Public status separates Application, API, and AI collections and shows incident history | A public status page is not a contractual uptime or support commitment | Obtain the applicable SLA, support channel, and escalation pathEvidence: Scrunch system status |
Checked 25 August 2026. A published control is evidence for diligence, but the executed agreement, security schedule, and current Trust Center documents govern procurement.
Does Scrunch have SOC 2 Type II, and what can procurement inspect?
Scrunch says it has completed SOC 2 Type II and links buyers to a Trust Center where reports are gated. It also publishes GDPR and CCPA alignment, role-based access, audit logs, and enterprise identity controls.
The practical diligence step is to request the current report, report period, system scope, bridge letter if needed, exceptions, penetration-test summary, and subprocessor list. The public claim alone does not answer those contract-level questions.
What do Scrunch SSO, provisioning, and user offboarding look like?
Enterprise supports SAML 2.0 and OIDC, just-in-time provisioning, and domain enforcement. Scrunch names standard identity-provider patterns and applies account permissions after login.
Its official SSO guide says SCIM is not supported. That means the buyer should document how users are removed, how dormant accounts are found, and whether identity-provider group changes update Scrunch roles automatically.
Can Scrunch isolate brands and produce an audit trail?
Scrunch documents Admin, Editor, and Viewer roles, an agency Guest role, and brand-level overrides to an organization role. That supports basic separation across brands and client workspaces.
Scrunch also states that comprehensive audit logs are available, but public pricing and security pages do not define the plan gate, logged events, retention, or export. Ask for a role matrix and a sample audit export.
What are Scrunch's data residency and contract options?
The public privacy policy permits processing and storage in the United States and other countries. We found no current public statement offering customer-selectable data residency.
Scrunch's public terms say a separate signed agreement can govern instead of the standard terms. Enterprise buyers should use that path to document location, transfers, retention, deletion, incident notice, subprocessors, and any required data-processing terms.
Does Scrunch publish reliability information and an SLA?
Scrunch operates a public status page with separate Application, API, and AI collections components plus incident history. That gives operations teams a public place to check service state.
The page does not itself establish a contractual uptime promise. Procurement should request the applicable SLA, severity definitions, response targets, support hours, maintenance terms, and service-credit process.
Evidence and method
A vendor-level SOC 2 claim is public
Scrunch states that it has completed SOC 2 Type II and routes report access through a Trust Center, giving security teams a concrete diligence starting point.
Evidence: Scrunch SOC 2 and security standardsIdentity support has a clear missing feature
SAML, OIDC, JIT provisioning, and domain enforcement are documented, while SCIM is explicitly absent, so lifecycle planning can address the gap directly.
Evidence: Scrunch SOC 2 and security standards, Scrunch single sign-on integrationRoles operate at organization and brand levels
The published role model includes brand-level overrides, which is material for enterprises and agencies separating access to multiple brands or clients.
Evidence: Scrunch user roles and permissionsResidency remains a written-answer item
The privacy policy permits international processing, but public security material does not describe selectable residency, so buyers should not infer a regional hosting promise.
Evidence: Scrunch Privacy Policy, Scrunch SOC 2 and security standardsNot publicly verified. A private enterprise arrangement may differ. Buyers with residency requirements should obtain the hosting region and transfer terms in writing.Operational status is publicly segmented
Separate Application, API, and AI collections components help teams distinguish a user-interface issue from data collection or developer-service availability.
Evidence: Scrunch system statusHow we checked this page
We checked Scrunch's current security, SSO, role, pricing, privacy, terms, and status material, separated public controls from gated evidence, and compared Trakkr from its current security page.
- 1. Mapped certification, identity, authorization, audit, residency, contract, and reliability statements to current first-party sources.
- 2. Marked plan details and contract terms as open when the public source names a feature without retention, export, entitlement, or regional scope.
- 3. Avoided treating policy language, a status page, or infrastructure controls as a substitute for a signed SLA or vendor-level certification.
- Limitation: We did not receive Scrunch's gated SOC 2 report, penetration-test material, security questionnaire, DPA, subprocessor list, or negotiated enterprise agreement.
- Limitation: Legal and security requirements differ by buyer, so this evidence map is not legal advice or a substitute for internal review.
When is Scrunch or Trakkr the stronger enterprise security fit?
Choose Scrunch when vendor-level SOC 2 Type II evidence is a firm procurement gate. Scrunch states it has completed that audit and also documents enterprise SSO, roles, audit logs, and a public service-status view.
Trakkr publishes strong technical controls including TLS 1.3, AES-256, row-level tenant isolation, role-based access, MFA, and regional isolation, but its security page explicitly says Trakkr does not currently hold its own SOC 2 certification.
Scrunch says it has completed SOC 2 Type II and makes reports available through a gated Trust Center. Buyers should request the current report and verify scope and period.
Scrunch Enterprise supports SAML 2.0 and OIDC with just-in-time provisioning and domain enforcement. Its current SSO guide explicitly says SCIM provisioning is not supported.
Yes at a public-claim level. Scrunch documents four role types and brand-level overrides, and says audit logs are available. Log retention, export, and plan gating remain public unknowns.
A customer-selectable residency option is not publicly documented. Scrunch's privacy policy permits processing and storage in the United States and other countries, so regional requirements need a written answer.
Scrunch's public terms state that a separate signed agreement can govern. That gives Enterprise buyers a path to negotiate security, privacy, service, and commercial terms.
Sources and related reading
See how AI talks about your brand
Enter your domain to get a free AI visibility report in under 60 seconds.