Security

How we protect your data and privacy.

Encryption

Account and API traffic uses HTTPS. Hosted account data relies on the database provider's encryption and access controls.

Sign-in credentials are handled by the authentication provider. ScamBrake does not store plaintext passwords in its application database.

Limited Permissions

ScamBrake requests permissions for supported sites and extension storage:

  • Check visible message content on enabled, supported sites
  • Store settings and preferences locally

We don't request access to your entire browsing history, downloads, or tabs you haven't opened.

Infrastructure

Hosted features are separated from the normal local scan. Operational controls include:

  • Environment-based secrets and authenticated API access
  • Row-level authorization for account data
  • Rate limiting and structured error handling
  • Cloud features that remain optional

Security Checks

Automated tests, type checks, linting, dependency review, and scoped code review are part of the release process. We do not claim an independent security audit unless one has been completed and published.

Report a Vulnerability

Found a security issue? We take it seriously. Report it responsibly:

  • Email: security@scambrake.com
  • Please include steps to reproduce and any proof-of-concept
  • We'll acknowledge receipt within 48 hours
  • We'll keep you updated on our progress

We follow responsible disclosure practices. Please give us reasonable time to fix issues before public disclosure.

Compliance

Account holders can request access, export, correction, or deletion through the privacy tools. For questions about applicable privacy rights, contact privacy@scambrake.com.

Bottom line: normal scans stay local, hosted features are optional, and each data flow should be understandable before you enable it.