Skip to content

Essential cookies run the site. Allow analytics to help us improve it? Cookie Policy

ScrumDo
How it worksBoards, flow, planning, and portfolio on one recordGoverned agentsBring your own agent with scoped context, provenance, approvals, and proofScrumDo MCPConnect Codex, Claude Code, Cursor, and other MCP clients to governed ScrumDo workScrumDo RunnerRun governed agents on your own machine, driven from the cardPortfolio & economicsConnect strategy, outcomes, investment, and delivery evidenceWardley strategy mappingCustomer needs, dependencies, and build-versus-buy choicesObjectives & key resultsMeasurable outcomes connected to epics, check-ins, and evidencePortfolio work typesTable stakes, spoilers, differentiators, cost reducers, and operating workJira coexistence & migrationExplore running alongside Jira or migrating workspaces and backlogsCustomer stories on the cardCustomer and process-improvement stories stay attached to the workPricing & plansTeam, Business, and Enterprise tiers with governed agents built in
Guides & governancePlanning, portfolio, flow, and governed-agent guidesAgent readiness assessmentScore one workflow across context, approvals, proof, and recoveryCustomer storiesFeedback from teams, educators, and coaches using ScrumDoPortfolio economicsCost of delay, budget context, and release tradeoffsFor agile coachesKanban-informed flow, classes of service, and governed agentsFor Kanban teamsWIP, classes of service, CFD, and process-improvement storiesFor SAFeWSJF, Lean budgeting, value streams, and release planningFor LeSSFeature teams, one product backlog, team-owned boardsFor Disciplined AgileChoose your way of working on one work recordFor PMP practitionersSchedule, dependencies, risk, and budget on the cardFor Lean and process improvementWIP, CFD, blocker clusters, and improvement as workCompare vendorsScrumDo vs Jira Align, Planview, Qualtrics, and othersAboutOur story, the product, and how we work with agents
Pricing
Log inSee plans

ScrumDo Trust & Governance

Version: 2.0
Effective Date: January 1, 2025
Last updated: July 11, 2026
Last Restated: July 11, 2026

ScrumDo is built for responsible sensemaking in high-stakes contexts. Our governance model emphasizes contributor care, methodological integrity, and clear accountability.

Security & Trust

ScrumDo maintains a formal information security program overseen by a designated Security Officer. Our security controls are selected based on annual risk assessments and mapped across industry frameworks including SOC 2, the HIPAA Security Rule, and the CSA Cloud Controls Matrix.

We follow the AWS shared responsibility model: AWS secures the cloud infrastructure, and ScrumDo secures the application and data layers running on it.

Certifications & Attestations

  • CSA STAR Level 1: Listed on the CSA STAR Registry, Level 1 Self-Assessment, CAIQ v4.1 covering 283 control questions across 17 control domains
  • SOC 2 Readiness Assessment: Independent licensed CPA review of documentation against the SOC 2 Security Trust Services Criteria completed April 2026, with alignment to the HIPAA Security Rule and ISO/IEC 27001:2022 Annex A. Letter available to prospective customers under NDA.
  • SOC 2 Type II examination: Planned with a peer-reviewed CPA firm
  • Detailed security and testing materials are provided through controlled Enterprise diligence. Contact security@scrumdo.com.

Data Protection

  • Encryption at rest: All data stored in databases and object storage is encrypted using AES-256 via AWS Key Management Service
  • Encryption in transit: Supported public service endpoints use TLS 1.2 or higher
  • Access controls: Role-based access control limits data access to authorized users, with SSO support for Microsoft Entra ID and Google Workspace
  • Audit logging: Security-relevant events are captured with full context including identity, action, timestamp, and source

Infrastructure

ScrumDo is hosted on Amazon Web Services. Hosting and processing locations are governed by the applicable service configuration, enabled features, subprocessor operations, and any Order Form, DPA, proposal, or security review commitments. These public materials describe ScrumDo's general posture and should not be read as a single-region hosting commitment.

  • AWS cloud infrastructure with encryption, logging, backup, and recovery controls
  • application deployment controls aligned to change and availability requirements
  • network segmentation and access controls appropriate to deployment scope
  • controlled review of detailed architecture artifacts under NDA or procurement review

Operational Security

  • Change management: Production changes follow documented review, testing, and deployment controls appropriate to the affected surface
  • Incident response: Documented incident response plan with defined severity levels, response procedures, and post-incident review
  • Business continuity: Automated database backups, documented disaster recovery procedures, and recovery testing
  • Vendor security: Third-party vendors assessed for security risk before onboarding with contractual safeguards

Account Governance

Account Owners control who receives Manager, Business Manager, billing, security, and organization-level administrative access. These roles expose different surfaces and do not imply one another.

An Account Owner may grant a coach, consultant, agency, contractor, or similar external practitioner scoped access where the plan permits. The Account Owner remains responsible for authorization, confidentiality, scope, duration, and removal of that access.

Account Owners are responsible for the notices, consent, lawful basis, access, retention, and safeguards that apply to Personal Information collected through their Rooms, Boards, customer-contribution routes, and connected services. Sensitive or regulated deployments may require an Enterprise agreement and security or privacy review.

To discuss a sensitive deployment or access model, contact support@scrumdo.com.

Healthcare & HIPAA

ScrumDo supports HIPAA-aligned deployments for healthcare organizations. The platform is designed to support administrative, physical, and technical safeguards required by the HIPAA Security Rule.

  • Business Associate Agreement (BAA) available for eligible customers
  • Infrastructure hosted on AWS with AWS BAA in place
  • Comprehensive audit logging and access controls
  • Documented incident response and breach notification procedures
  • Annual risk assessments aligned with NIST SP 800-66

HHS/OCR does not certify products or organizations as "HIPAA compliant." Our HIPAA program reflects our commitment to operating in accordance with the HIPAA Security Rule when handling protected health information under a BAA.

Privacy

We design for data minimization, clear purpose boundaries, and transparent handling of user and contributor data. Our privacy commitments and legal terms are published and maintained in one place.

  • Privacy policy: /legal/privacy-policy
  • Cookie policy: /legal/cookie-policy
  • Data processing agreement: /legal/data-processing-agreement
  • Subprocessors: /legal/data-subprocessors

Regional Privacy Readiness

ScrumDo supports customer-led privacy and security review for deployments involving the EU/EEA, United Kingdom, Australia, New Zealand, and other jurisdictions where project context requires additional review.

Region-specific requirements are scoped through the applicable order form, DPA, pilot proposal, or security review package. This may include hosting-region expectations, transfer safeguards, customer notice responsibilities, subprocessor review, retention expectations, access controls, deployment-specific restrictions, and proposal annexes for regulated or public-sector work.

Public legal pages provide summary posture. Detailed jurisdictional responses, data-flow diagrams, security questionnaire answers, and project-specific control mappings are shared through proposal or controlled diligence workflows.

AI and Bring-Your-Own-Agent Boundary

ScrumDo does not train a proprietary foundation model on Customer Content. AI in ScrumDo falls into three categories, and the data handling differs by category.

1. Bring-Your-Own-Agent (local agents). You may connect a coding agent (e.g., Claude Code, Codex, Grok, GitHub Copilot, Cursor) that runs on your own machine or infrastructure under your own provider account and keys. In this mode ScrumDo orchestrates the workflow and records the outcome, but does not transmit your Content to the model provider or authenticate the model call; your agent does, in an environment you control.

2. Customer-configured AI features ("Connected AI"). You may enable optional features that use the AI provider and API key you configure ("your Connected AI Provider"), such as spec-drift detection, behavior verification, cross-card consistency analysis, managed agent execution, or AI-assisted data transformation. When you enable one, ScrumDo transmits the relevant Content to your Connected AI Provider, on your behalf and authenticated with your key. Depending on the feature, that Content may include card specifications, related-card summaries, or a read-only snapshot of connected-repository files. The provider operates under your account and your agreement with it. For organizational use, the Customer is responsible for determining the parties' roles under applicable law, the lawfulness of the instruction, and any required transfer safeguards. ScrumDo processes this Content only on your instruction through your configuration of the feature. These features are off until you enable them.

3. ScrumDo operational AI. ScrumDo uses AI under its own provider account for limited operational features, currently support-ticket assistance (summaries and suggested replies). For these, the AI provider is ScrumDo's sub-processor, listed on our Sub-processors page, and processes only the relevant support content.

Your Content, your responsibility. You control what Content you place in ScrumDo. For Customer-configured AI, ScrumDo does not independently select or add personal information to the Content you direct to the provider; it transmits the Content and feature inputs you configure. You are responsible for the Content you submit, including any personal or sensitive information you include even inadvertently, and for the decision to route it to an AI feature. ScrumDo is not responsible for personal information a customer places in the platform that a feature the customer enabled then transmits.

No guarantees. AI-assisted and automated outputs across all three categories are provided "as is," may be inaccurate or incomplete, are not a substitute for human review, and you remain responsible for decisions made using them. Whether your Content is retained or used to improve a model is governed by your agreement with the relevant provider; for ScrumDo operational AI, we contract for no training on your content where the provider offers it.

Where enabled, automated or third-party services may support transcription, translation, and PII redaction. These outputs may contain errors and should be reviewed by humans before use.

Customers remain responsible for deciding whether transcription, translation, or PII redaction is appropriate for their context, contributor notice, and legal basis. Feature-specific subprocessors and processing purposes are described in the Privacy Policy, DPA, Subprocessors List, and applicable account materials.

Notifications and Connected Destinations

ScrumDo keeps notification preferences, watches, acknowledgement state, routing decisions, and delivery status on the governed record. Account Owners may configure external delivery through email, SMS, WhatsApp, Slack, Microsoft Teams, push, or webhooks. External channels draw attention to the work; they do not replace the in-product source of truth or required acknowledgement record.

Account Owners control which categories may be delivered externally, who or which workspace receives them, and which provider credentials are used. ScrumDo applies channel eligibility, consent, suppression, rate, and destination checks before supported delivery. Customer-configured providers operate under the Customer's agreement. Providers contracted by ScrumDo are listed on the Subprocessors page.

Compliance

ScrumDo maintains published compliance and governance documentation for partners, customers, and procurement teams.

  • Accessibility, quality-management, control-mapping, and change-management materials are provided during applicable procurement or Enterprise diligence. Contact security@scrumdo.com.

Partner Standards

ScrumDo partnerships are stewardship-based and quality-governed. We prioritize delivery integrity, role clarity, and contributor protection over volume.

  • Partner terms and engagement boundaries are provided as part of the applicable partner agreement.

Customer Evidence and Contribution Routes

ScrumDo can collect customer evidence through different governed routes. A configured route may collect a story without creating a card, create a card through intake, or allow a registered Customer Contributor to create and track customer-visible work.

  • Identity mode and visibility must be stated accurately.
  • Anonymous, pseudonymous, confidential, and identified routes are not interchangeable.
  • Customer Contributors do not receive internal Account access solely by submitting Content.
  • Account Owners remain responsible for notices, consent, lawful basis, use, retention, and follow-up.
  • ScrumDo does not guarantee response counts, representativeness, or outcomes.

Intellectual Property & Licensing

ScrumDo owns the proprietary intellectual property in the current ScrumDo platform, including ScrumDo-developed software, ScrumDo trademarks and brand assets, and original ScrumDo documentation and content. ScrumDo holds the rights necessary to commercialize and license the platform and related services worldwide. Certain third-party components are used under their applicable license terms.

Any references to third-party organizations, methods, or products are for identification purposes only and do not imply affiliation, endorsement, or sponsorship.

Governance Controls

ScrumDo applies internal controls for external communications and partner-facing materials, including:

  • legal and commercial review for public claims
  • attribution and licensing checks for third-party materials
  • correction and escalation procedures when issues are identified

Contact

For security inquiries, to request SOC 2 readiness materials (under NDA), or to discuss a BAA: security@scrumdo.com

For diligence, legal, IP, or governance questions: legal@scrumdo.com

See the full legal overview. This page is provided for reference; for the controlling agreement applicable to your account, contact ScrumDo.

ScrumDoKeep customer stories connected to the work.

Plan, deliver, and review with your team and your agents in one place.

Product

How it works Governed agents Portfolio & economics Jira coexistence & migration Customer stories on the card Pricing & plans
More product details
ScrumDo MCPScrumDo RunnerWardley strategy mappingObjectives & key resultsPortfolio work typesStrategy streamsPortfolio budgetingRelease planningAgents overview

Learn & compare

Guides & governance Customer stories For Kanban teams For SAFe Compare vendors About
More roles & resources
Agent readiness assessmentPortfolio economicsFor agile coachesFor product & engineering leadersFor PMO leadersFor regulated industriesFor LeSSFor Disciplined AgileFor PMP practitionersFor Lean and process improvementSecurity & TrustWelcome back

Get started

See plansAssess one workflowLog in
PrivacyTermsCookiesGDPRSecurityAll legal

© 2026 ScrumDo LLC. All rights reserved.

Other product names, logos, and brands are the property of their respective owners; references are for identification and comparison only and do not imply affiliation or endorsement.