SFScoutform AI

Security and data handling

Clear controls, without invented trust badges.

This is a practical account of the controls Scoutform uses today. Scoutform does not currently claim SOC 2 or ISO 27001 certification.

Server-only secrets

OpenAI, Stripe, Resend, and Supabase service credentials stay in server environment variables and are not shipped in the public widget.

Account and row access

Supabase authentication identifies account owners. Row-level security policies restrict customer-facing database access to owned business records.

Validated requests

Public and authenticated API routes validate input, restrict payload size, and rate-limit repeated requests. Stripe webhook signatures are verified.

Grounded AI answers

Business answers use retrieved knowledge sources. Internal source metadata is stored with assistant messages so responses can be reviewed.

Payment separation

Stripe hosts checkout and billing management. Scoutform stores subscription identifiers and status, not customer card numbers.

Incident contact

Security or privacy concerns can be reported directly to hcook.24@wymcol.org. Reports are reviewed manually.

Data lifecycle

Retention and deletion

Account, business, knowledge, chat, and lead records are retained while they are needed to provide the service or until the account owner removes them or requests deletion.

Some billing, fraud-prevention, backup, or operational records may remain for a reasonable period where required for legal, accounting, security, or service-recovery purposes.

To request access, correction, export, restriction, or deletion, email hcook.24@wymcol.org.

Service providers

Core subprocessors

Supabase

Authentication, PostgreSQL data storage, and vector retrieval

OpenAI

Embeddings and grounded assistant responses

Stripe

Checkout, subscriptions, invoices, and billing portal

Resend

Lead and contact notification email delivery

Vercel

Application hosting, server functions, and optional consented analytics

Responsible use

Important limits

Businesses remain responsible for checking important prices, availability, regulated advice, and claims before relying on AI-generated responses.

Scoutform should not be used to collect unnecessary sensitive data or provide emergency, medical, legal, or financial decisions without appropriate human review.

See the privacy policy and terms of service for the broader data and acceptable-use position.