Talon Scout · Security

Security

Effective 22 August 2026 · scout.talonaudit.com

← back to Talon Scout  ·  Privacy  ·  Terms  ·  Security


How Talon Scout protects the data that passes through it.

Architecture

Data handling

No submitted targets or generated cards are stored by the service. Only per-IP rate-limit counters (10 requests/minute) are kept in Cloudflare KV for 60 seconds. Scan results exist only in your browser session.

Transport and headers

All traffic is HTTPS with TLS 1.2+. Every response carries security headers: HSTS, Content-Security-Policy, X-Frame-Options: DENY, X-Content-Type-Options: nosniff, Referrer-Policy, Permissions-Policy, and Cross-Origin isolation headers.

Third parties

Third-party processors may handle the target's public content transiently: Firecrawl and Apify (page scraping) and DeepSeek (card summarization). All API keys are held server-side as Cloudflare Worker secrets and never shipped to the browser.

Disclosure

Security findings can be reported via /.well-known/security.txt on the service domain or by email to info@raptorlabs.dev.

Limitations (honest)

Talon Scout is a demonstration-grade tool, not a compliance product. It does not hold third-party compliance certifications, and its rate limiting relies on an eventually consistent platform store — treat it as a throttle, not a security boundary.