Account and data access
Supabase authentication protects account access. Row-level database policies keep each business's leads, chats, settings, and knowledge sources separated from other customers.
Scoutform security
Scoutform handles business knowledge and visitor contact details, so its safeguards are part of the product, not a claim added after the fact. This page explains the controls currently built into the service.
Last reviewed 11 September 2026
Supabase authentication protects account access. Row-level database policies keep each business's leads, chats, settings, and knowledge sources separated from other customers.
OpenAI, Stripe, Resend, and Supabase service credentials stay in server-only environment variables. They are not included in the browser widget or public JavaScript bundle.
Public API inputs are validated before use. Shared rate limits protect signup, contact, chat, lead capture, uploads, and website scanning from repeated automated requests.
Scoutform retrieves approved business sources before answering. When the available information is not enough, the assistant is instructed to say so and offer a human follow-up rather than inventing details.
Stripe Checkout handles card entry and subscription payments. Scoutform stores subscription references and status, not card numbers. Stripe webhook signatures are checked before billing events are accepted.
Security or privacy concerns can be reported directly to cook@cbn.net.id. Include the affected page and enough detail to reproduce the issue, but do not include passwords, API keys, or unnecessary personal data.
Read the privacy policy for the data lifecycle, or contact the operator directly before installing Scoutform.