Security

Where your data sits, and who can see it

The short version: in Solo mode, rows stay in your browser — there is no server. In Team mode, rows sync to a Postgres database we host. There is no third-party proxy in the loop on either.

01

Data locality

In Solo mode, the leads you harvest persist in the browser's own extension storage (chrome.storage.local). There is no server, no account, no telemetry — nothing leaves the laptop. In Team mode, leads sync to a Postgres database we host. You can leave Team mode at any time and export the full table to Excel, CSV, or NDJSON.

02

Processing

All harvesting happens in your browser at the speed you drive. There is no headless farm, no third-party proxy, no remote browser in the loop. Calling runs over WebRTC in your own browser; carrier minutes are handled through standard telephony sub-processors.

03

Encryption

In transit: TLS 1.3 across every public endpoint. At rest: standard disk encryption on the database host (the host itself, not column-level — column-level encryption for phone numbers is a TODO before launch). Session cookies are httpOnly + secure + sameSite=lax.

04

Access control

Workspaces have four roles — owner, admin, manager, member. Reps see only their own leads; managers see the leads assigned to the team they manage; admins and owners see the whole workspace. There is no implicit cross-workspace visibility — every request is scoped to the workspace in its bearer token.

05

Audit logging (planned)

Every write to a lead, pipeline, view, or workspace setting will be logged with actor, timestamp, before-value, and after-value. Audit logs are on the roadmap for the Team plan — they are not yet shipped. The plan ships with `audit_log` placeholders wired up to the auth layer so the surface is real but the rows are empty.

06

Reporting a vulnerability

Email security@scraper.example (placeholder — replace with the real address before launch). We acknowledge within 24 hours and follow up with what we found. We do not run a paid bug-bounty program yet.

Something we should know?

Report a vulnerability or ask a security question — we answer within one business day.