Security and data handling
Prospect Scout is built to meet SOC 2 control expectations. The controls below are in place today; a formal SOC 2 report is on the roadmap.
Controls
- Tenant isolation
- Every workspace table is protected by Postgres row-level security policies, tested in CI. Shared public-source data (filings, news) never carries workspace identity.
- Authentication
- Email and password or magic link, optional TOTP two-factor per user, and workspace-wide two-factor enforcement. SAML SSO is available on enterprise plans.
- Audit logging
- Sign-ins, membership changes, imports, exports and configuration changes are recorded in an append-only audit log visible to workspace admins.
- Encryption
- TLS in transit; AES-256 at rest for the database and backups. Secrets live only in the hosting platform’s encrypted environment.
- Data lifecycle
- Workspace admins can export all data and delete the workspace. Deletion is final after a 7-day grace period. Free-trial data expires after 30 days.
- Abuse protection
- Public endpoints are rate limited and protected by a bot challenge. Third-party sources are fetched within their published rate limits.
Subprocessors
All subprocessors hold current SOC 2 Type II reports.
- VercelApplication hosting (US)
- SupabasePostgres database, authentication, storage (US)
- InngestBackground job orchestration
- AnthropicLanguage-model processing of public documents and your ICP; web search for research questions
- PerplexityWeb search for research questions about companies and public social posts
- ResendTransactional email
- CloudflareBot challenge on public forms
- SentryError monitoring (no signal or contact content)
Data sources
Signals and account facts come from public sources and from the tools you connect. We honor each source's published rate limits and terms, and do not bypass logins or paywalls.
- Company filings
- SEC EDGAR: annual and quarterly reports, current reports (8-K), proxy statements, investor materials and Form D private-capital filings.
- News and press
- News coverage, press-release wires and company newsrooms.
- Hiring
- Public job postings on company career sites and their applicant-tracking systems.
- Public technical footprint
- Public DNS records, certificate-transparency logs and published email and security settings. When a rep runs a tech scan with the confirm step on, one request to a public page on each matching host.
- Public code
- Public repositories of company GitHub organizations.
- Regulators
- Government breach notices and enforcement actions (state attorneys general, SEC, FTC and banking regulators).
- Web research
- Web search, through the subprocessors above, for research questions and public social posts.
- Events and interviews
- Public conference listings and public video interviews with company executives.
- Tools you connect
- Your own Apollo or ZoomInfo account for contact data, and each rep’s own LinkedIn through the browser extension, only while they choose to. Nothing from one workspace’s connections reaches another.
How every claim is traced
- Every signal, technology fact and person links to the page, filing, posting or record it came from, with the date it was checked; a person from a tool you connected (for example your Apollo account) names that tool instead.
- Text written by the language model (why a signal matters, briefs, research answers, outreach drafts) is marked AI and shown alongside the sources it drew on, so it can be checked.
- We keep each source's link, the date we read it and a fingerprint of what it said for as long as the claim is shown. We store short excerpts, not full copies of pages.
- Our team can trace any claim back to the run that collected it, so a question about where something came from always has an answer.