Security
Security and data handling
Case data belongs to the person who reported it. This page explains the controls that enforce that.
ScamGuard Pro staff will never ask for your password, wallet private key, seed or recovery phrase, banking PIN, card CVV or a one-time passcode. Anyone who does is impersonating us — report it via report abuse.
Access control
- Case records, messages and evidence are readable only by the case owner and assigned staff.
- Access rules are enforced at the database level, not only in the interface.
- Staff roles are stored separately from user profiles and cannot be self-assigned.
- Sensitive administrative actions are recorded in an audit log.
Evidence storage
- Uploads are held in a private storage bucket, never in a public folder.
- Files are served through short-lived signed links generated for authorised users only.
- Each file keeps its case association, uploader and timestamp for chain-of-record purposes.
Communication
- Case conversations happen only inside your signed-in ScamGuard Pro case.
- Messages are scanned for sensitive content patterns before sending, and you are warned.
- You can report any message that requests credentials or payment.
Account security
- Authentication uses managed, industry-standard credential storage — we never store raw passwords.
- Sessions can be ended at any time by signing out.
- Email confirmation is required so cases cannot be created against addresses you do not control.
Reporting a vulnerability
If you believe you have found a security issue, tell us through contact with enough detail to reproduce it. Please do not publish the issue before we have responded.