Trust Center
Security & privacy at PrivacyScan
This page is maintained by the PrivacyScan team to answer common security and privacy questions about the platform. It describes controls that are currently enabled and how responsibilities are shared between PrivacyScan, its infrastructure providers, and customers. It is not an independent certification.
Authentication & access control
- Email & password sign-in with password strength meter and leaked-password checks.
- Google single sign-on via an OAuth broker.
- Workspace roles (owner, admin, member) with per-scan collaborator roles.
- Row-level security enforced on every user-owned table.
- Signed report hashes so shared reports can be verified against the original scan.
Platform & hosting
PrivacyScan runs on Cloudflare's edge runtime for application logic and on managed PostgreSQL (Supabase) for storage. TLS is enforced end-to-end. Application secrets are held in the managed secret store and never checked into source control.
Data collection & use
We store scan targets, scan results, findings, and the metadata needed to operate the product (accounts, workspaces, invites, billing state). We do not sell customer data and do not use it to train third-party AI models. See the Privacy Policy for the full description.
Subprocessors
A current list of subprocessors is maintained at /legal/subprocessors.
Retention & deletion
Scans and findings are retained until the workspace owner deletes them or closes the account. Account deletion is available from the profile page and removes user-owned data on request.
Security contact & incident response
Report a suspected vulnerability or incident to security@privacytoolbox.ng. Machine-readable disclosure metadata is published at /.well-known/security.txt.
Data Processing Agreement
A standard DPA is available at /legal/dpa. Custom terms for enterprise customers are available on request.
Regulation coverage
PrivacyScan maps findings to NDPA 2023, GAID 2025, GDPR, UK-GDPR, CCPA/CPRA, LGPD, PIPEDA, POPIA, PDPA (Singapore), DPDP Act (India), and the Australian Privacy Act. Coverage is intended as guidance and is not a legal opinion.
Acknowledgments
Thanks to the researchers who have privately disclosed issues. Names are added here on request.