1. Our approach
Security is built into how NumberScout is designed and operated. This page describes the main measures we use to protect your data as of August 28, 2026. Security is never "finished", so we review and improve these measures continuously. If you have questions or believe you have found a vulnerability, contact us at support@numberscout.org.
2. Encryption in transit
All traffic between your browser and NumberScout is encrypted with TLS (HTTPS) — every page, every search and every API request, with no exceptions. Plain HTTP requests are redirected to HTTPS, and we use modern TLS configurations and keep our certificates and cipher suites up to date. Data exchanged between our application and our infrastructure providers is likewise encrypted in transit.
3. Payments are handled by Stripe
We never see or store your full card number. All payments on NumberScout are processed by Stripe, a PCI DSS Level 1 certified payment provider. Your card details are entered into fields served and secured by Stripe and travel directly from your browser to Stripe's servers; our systems only receive a confirmation of the payment and limited billing metadata. This means a compromise of our systems could not expose your card number, and we could not read it even if we wanted to.
4. Least-privilege data access
Access to production systems and customer data follows the principle of least privilege: every credential, service and person gets the minimum access needed to do its job, and nothing more.
- Administrative database credentials are used only by trusted server-side code and are never shipped to the browser.
- Client-side code operates with restricted, scoped keys that can only perform the narrow operations the page needs.
- Human access to production data is limited to the small number of people who operate the service, protected by strong authentication.
- Secrets are stored in managed configuration, not in source code.
5. Data minimisation and retention
We collect only the data needed to run the service, and we keep it only as long as we need it, as described in our Privacy Policy. Technical logs are retained for limited periods for security monitoring and troubleshooting, then deleted or anonymised. When you ask us to delete your data, we remove it from active systems promptly and from backups on their normal expiry cycle.
6. Monitoring and incident response
We monitor the service for errors, abuse and unusual activity. If we ever determine that a security incident has affected your personal data, we will notify you and the relevant authorities as required by applicable law, explain what happened, and tell you what we are doing about it and what you can do to protect yourself.
7. Responsible disclosure
We welcome reports from security researchers. If you believe you have found a vulnerability in NumberScout, please email support@numberscout.org with the subject "Security" and include enough detail for us to reproduce the issue — the URL or endpoint affected, the steps you took, and what you observed. Please give us a reasonable amount of time to investigate and fix the issue before disclosing it publicly, do not access or modify data that is not yours, and do not run tests that could degrade the service for others. We will acknowledge your report, keep you informed as we work on a fix, and credit you for the discovery if you would like us to.
8. Your part
A few simple habits keep your account safe: use a unique password for every service, keep your email account secure since it is used to manage your subscription, and be wary of emails claiming to be from NumberScout that ask for payment details — we will never ask for your card number by email. Anything suspicious can be forwarded to support@numberscout.org and we will look into it.
