Azure-hosted services
Scout runs as separate web, API and worker services with managed database, secrets and telemetry services.
Security and trust
Scout uses established cloud providers, keeps evidence and customer workflow separate, and labels generated interpretation. The current posture is described without unsupported certification claims.
Buyer-facing summary
Scout runs as separate web, API and worker services with managed database, secrets and telemetry services.
Local passwords are hashed; API access uses signed tokens and can validate Microsoft Entra ID when configured.
Public evidence, customer workflow and generated interpretation remain distinct.
Stripe handles payment methods where billing applies; the marketing site never receives Scout sessions or secrets.
Generated summaries are grounded in stored notice facts, stored separately and visibly labelled.
Technical detail
These notes describe the reviewed architecture now. Ask for organisation-specific evidence if your procurement process needs more.
Scout is deployed as separate API, web and ingestion-worker services on Azure Container Apps. Azure Database for PostgreSQL stores application data; Key Vault supplies deployment secrets; Application Insights receives operational telemetry.
Current production parameters target Azure UK South. Alert e-mail uses Azure Communication Services Email with its data location configured as UK. This is not a blanket claim that every provider or backup is UK-only.
The API uses JWT bearer tokens. Local accounts use hashed passwords, and Microsoft Entra ID tokens can be accepted when the relevant settings are configured.
Saved searches, buyer follows, tags, notes, exports and settings are customer-account scoped, with user attribution where the workflow records it. Secrets such as signing keys and provider credentials are configuration, not source code.
Raw public records are retained before transformation. Normalised fields support search and buyer context without overwriting original values or identifiers.
The ingestion worker creates notice summaries from stored facts such as title, description, buyer, stage, value, deadline, location and CPV codes. Account notes, tags and saved searches are not sent for summary generation. The web app reads the stored result rather than generating during a page view.
Scout Free has no checkout. Stripe portal, webhook and subscription infrastructure remains dormant for historical subscriptions and future paid Winston capabilities; Stripe handles payment-method collection when billing applies.
The public website is a separate static application. It links to Scout but does not receive Scout cookies, API credentials or product secrets. Winston Intelligence does not currently claim ISO 27001, SOC 2, completed penetration testing, formal uptime guarantees or complete UK procurement coverage.
Procurement review
Send the requirement or questionnaire context and we will answer what the current product can support.
Ask a security question