Gapscope

Beta Security Overview

Updated August 7, 2026

Current controls

  • Encrypted web connections for normal browser traffic.
  • Account and server-side ownership checks on private routes.
  • A private advisor database area that is not exposed through the public browser database client.
  • Application-level encryption for selected identity, contact, fact, calculation, quote, and note fields.
  • Hashed lookup values where the app needs to match protected data.
  • Rate limits, short-lived client access, and database-protected append-only records for support-improvement approvals.
  • Human approval gates for product suggestions, application destinations, code changes, and live launch.

Important limits

Gapscope has not completed a SOC 2 audit and does not claim to be FINRA-certified, HIPAA-certified, or immune from security failures. Some older beta paths are still being replaced. A control described here is not a promise that every kind of risk has been removed.

The beta should not be used to store Social Security numbers, bank or routing numbers, passwords, medical records, prescriptions, or detailed diagnoses. Advisors should use the smallest amount of client information needed for the planning conversation.

Report a security concern

Email security@gapscope.io. Include the route, time, and a short description. Do not email client data, passwords, access tokens, or proof that exposes another person's information. Gapscope will confirm receipt and handle the report privately.

Launch status

This overview still requires security and counsel review before a broad public launch. The controlled beta remains the current scope.

Back to gapscope.io