Security
How we protect your data and privacy.
Encryption
Account and API traffic uses HTTPS. Hosted account data relies on the database provider's encryption and access controls.
Sign-in credentials are handled by the authentication provider. ScamBrake does not store plaintext passwords in its application database.
Limited Permissions
ScamBrake requests permissions for supported sites and extension storage:
- Check visible message content on enabled, supported sites
- Store settings and preferences locally
We don't request access to your entire browsing history, downloads, or tabs you haven't opened.
Infrastructure
Hosted features are separated from the normal local scan. Operational controls include:
- Environment-based secrets and authenticated API access
- Row-level authorization for account data
- Rate limiting and structured error handling
- Cloud features that remain optional
Security Checks
Automated tests, type checks, linting, dependency review, and scoped code review are part of the release process. We do not claim an independent security audit unless one has been completed and published.
Report a Vulnerability
Found a security issue? We take it seriously. Report it responsibly:
- Email: security@scambrake.com
- Please include steps to reproduce and any proof-of-concept
- We'll acknowledge receipt within 48 hours
- We'll keep you updated on our progress
We follow responsible disclosure practices. Please give us reasonable time to fix issues before public disclosure.
Compliance
Account holders can request access, export, correction, or deletion through the privacy tools. For questions about applicable privacy rights, contact privacy@scambrake.com.
Bottom line: normal scans stay local, hosted features are optional, and each data flow should be understandable before you enable it.