SFScoutform AI

Scoutform security

Practical protection for every lead conversation.

Scoutform handles business knowledge and visitor contact details, so its safeguards are part of the product, not a claim added after the fact. This page explains the controls currently built into the service.

Last reviewed 11 September 2026

Account and data access

Supabase authentication protects account access. Row-level database policies keep each business's leads, chats, settings, and knowledge sources separated from other customers.

Protected application secrets

OpenAI, Stripe, Resend, and Supabase service credentials stay in server-only environment variables. They are not included in the browser widget or public JavaScript bundle.

Safer data handling

Public API inputs are validated before use. Shared rate limits protect signup, contact, chat, lead capture, uploads, and website scanning from repeated automated requests.

Grounded AI answers

Scoutform retrieves approved business sources before answering. When the available information is not enough, the assistant is instructed to say so and offer a human follow-up rather than inventing details.

Payment processing

Stripe Checkout handles card entry and subscription payments. Scoutform stores subscription references and status, not card numbers. Stripe webhook signatures are checked before billing events are accepted.

Responsible reporting

Security or privacy concerns can be reported directly to cook@cbn.net.id. Include the affected page and enough detail to reproduce the issue, but do not include passwords, API keys, or unnecessary personal data.

Questions about your data?

Read the privacy policy for the data lifecycle, or contact the operator directly before installing Scoutform.