Security

    Updated: 2026-08-12

    Reporting a vulnerability

    Email support@scanchess.com with "Security" in the subject. Describe how to reproduce it and what it lets someone do. We reply within 3 business days and tell you the outcome once it is fixed.

    We will not pursue legal action over good-faith research, provided you do not access, change, or exfiltrate anyone else's data, do not run denial-of-service or spam tests, and give us a chance to fix the issue before disclosing it. There is no paid bounty programme, but we will credit you by name if you want that.

    How your data is protected

    • Everything travels over HTTPS; the site and API sit behind Cloudflare.
    • Passwords are stored as salted bcrypt hashes — we cannot read yours.
    • Web sessions use signed JWTs in HttpOnly cookies; changing a password revokes previously issued sessions and password-reset tokens.
    • We never handle payment details: web checkout is hosted by Waffo, our merchant of record, and we receive only an order id and subscription status.
    • Deleting an account really deletes it — profile, games, and uploaded images go, and cannot be recovered.

    The images you upload

    Scoresheet photos are sent to the third-party AI model provider we use for recognition; the Privacy Policy sets out exactly what is shared. Images belong to your account: delete a single game at any time, or delete the account to remove all of them.

    What we do not have

    Plainly: no SOC 2, no ISO 27001, no third-party audit, and no paid bounty programme. ScanChess is built by a small team. If your school, federation, or employer needs compliance paperwork, write to us and we will tell you honestly what we can and cannot provide.