Security and trust

What a buyer needs to know, with the detail underneath.

Scout uses established cloud providers, keeps evidence and customer workflow separate, and labels generated interpretation. The current posture is described without unsupported certification claims.

Working ruleEvidence stays visible.Interpretation stays labelled.

Buyer-facing summary

Five boundaries that carry the trust story.

Azure-hosted services

Scout runs as separate web, API and worker services with managed database, secrets and telemetry services.

Secure account access

Local passwords are hashed; API access uses signed tokens and can validate Microsoft Entra ID when configured.

Separated data

Public evidence, customer workflow and generated interpretation remain distinct.

Provider boundaries

Stripe handles payment methods where billing applies; the marketing site never receives Scout sessions or secrets.

Responsible AI

Generated summaries are grounded in stored notice facts, stored separately and visibly labelled.

Technical detail

Inspect the implementation-level claims.

These notes describe the reviewed architecture now. Ask for organisation-specific evidence if your procurement process needs more.

Hosting and operations

Scout is deployed as separate API, web and ingestion-worker services on Azure Container Apps. Azure Database for PostgreSQL stores application data; Key Vault supplies deployment secrets; Application Insights receives operational telemetry.

Current production parameters target Azure UK South. Alert e-mail uses Azure Communication Services Email with its data location configured as UK. This is not a blanket claim that every provider or backup is UK-only.

Authentication and account scope

The API uses JWT bearer tokens. Local accounts use hashed passwords, and Microsoft Entra ID tokens can be accepted when the relevant settings are configured.

Saved searches, buyer follows, tags, notes, exports and settings are customer-account scoped, with user attribution where the workflow records it. Secrets such as signing keys and provider credentials are configuration, not source code.

Evidence and generated content

Raw public records are retained before transformation. Normalised fields support search and buyer context without overwriting original values or identifiers.

The ingestion worker creates notice summaries from stored facts such as title, description, buyer, stage, value, deadline, location and CPV codes. Account notes, tags and saved searches are not sent for summary generation. The web app reads the stored result rather than generating during a page view.

Billing, website and current limits

Scout Free has no checkout. Stripe portal, webhook and subscription infrastructure remains dormant for historical subscriptions and future paid Winston capabilities; Stripe handles payment-method collection when billing applies.

The public website is a separate static application. It links to Scout but does not receive Scout cookies, API credentials or product secrets. Winston Intelligence does not currently claim ISO 27001, SOC 2, completed penetration testing, formal uptime guarantees or complete UK procurement coverage.

Procurement review

Need a specific answer for your buyer?

Send the requirement or questionnaire context and we will answer what the current product can support.

Ask a security question