Security

Boundaries first. Claims second.

ScriptByrd records the difference between queued, attempted, delivered, acknowledged, completed, and independently verified actions.

Last updated 27 August 2026

Account and tenant controls

ScriptByrd requires organisation membership, server-side authorisation and database row-level security for account data. If those controls are unavailable, account actions are unavailable too. A user can belong to more than one organisation.

Tokens and redemption codes

Invitation delivery is not currently offered. A redemption form is exposed only to a signed-in account when ScriptByrd can validate the code safely. Activation codes are entered in a form, never placed in the URL or analytics, and are hashed before database matching. Failures use a generic response so the page does not reveal whether a particular code exists.

Audit and evidence

Privileged and material case events are written to append-only histories. Important events can be hash-chained and evidence objects can receive SHA-256 receipts over original bytes or documented canonical data. The phrase used for this property is “tamper-evident integrity and custody record.”

Deliberate exclusions

ScriptByrd does not connect to bank accounts, request banking credentials, analyse bank statements, or move, hold, redirect or stop money. External messages and outcomes appear only when the corresponding delivery or response evidence is available.

Reporting a security concern

A monitored security-report destination has not yet been verified, so this page does not expose an unproved contact action. Do not send credentials, access tokens, redemption codes, banking details, or private case content to an address you cannot verify. No independent security certification is claimed on this page.