Prospect Scout

Security and data handling

Prospect Scout is built to meet SOC 2 control expectations. The controls below are in place today; a formal SOC 2 report is on the roadmap.

Controls

Tenant isolation
Every workspace table is protected by Postgres row-level security policies, tested in CI. Shared public-source data (filings, news) never carries workspace identity.
Authentication
Email and password or magic link, optional TOTP two-factor per user, and workspace-wide two-factor enforcement. SAML SSO is available on enterprise plans.
Audit logging
Sign-ins, membership changes, imports, exports and configuration changes are recorded in an append-only audit log visible to workspace admins.
Encryption
TLS in transit; AES-256 at rest for the database and backups. Secrets live only in the hosting platform’s encrypted environment.
Data lifecycle
Workspace admins can export all data and delete the workspace. Deletion is final after a 7-day grace period. Free-trial data expires after 30 days.
Abuse protection
Public endpoints are rate limited and protected by a bot challenge. Third-party sources are fetched within their published rate limits.

Subprocessors

All subprocessors hold current SOC 2 Type II reports.

Data sources

Signals and account facts come from public sources and from the tools you connect. We honor each source's published rate limits and terms, and do not bypass logins or paywalls.

Company filings
SEC EDGAR: annual and quarterly reports, current reports (8-K), proxy statements, investor materials and Form D private-capital filings.
News and press
News coverage, press-release wires and company newsrooms.
Hiring
Public job postings on company career sites and their applicant-tracking systems.
Public technical footprint
Public DNS records, certificate-transparency logs and published email and security settings. When a rep runs a tech scan with the confirm step on, one request to a public page on each matching host.
Public code
Public repositories of company GitHub organizations.
Regulators
Government breach notices and enforcement actions (state attorneys general, SEC, FTC and banking regulators).
Web research
Web search, through the subprocessors above, for research questions and public social posts.
Events and interviews
Public conference listings and public video interviews with company executives.
Tools you connect
Your own Apollo or ZoomInfo account for contact data, and each rep’s own LinkedIn through the browser extension, only while they choose to. Nothing from one workspace’s connections reaches another.

How every claim is traced