Skip to main content
    Scalexa — Senior Engineering & AI Solutions

    Trust, Security & Privacy

    Last updated: 1 October 2026

    This page is maintained by Scalexa to answer common security and privacy questions about scalexa.ai. It describes the controls on this website today. It is not an independent certification or audit.

    Scope

    This statement covers the public marketing website at scalexa.ai and the protected client-facing reports and dashboards hosted on the same site (for example the AWS WAFR dashboard and security assessment reports). It does not cover engagements delivered for clients in their own environments, which are governed by the contract in place for that engagement.

    Authentication & access

    • The public website does not require an account to browse.
    • Protected client reports (e.g. AWS WAFR and password-gated security assessment reports) are guarded by a server-side password check, with short-lived signed access tokens stored in the browser session and re-verified on reload.
    • Password verification runs in serverless edge functions; passwords are stored only as bcrypt hashes and are never returned to the browser.

    Hosting & platform

    • The website is built with React and Vite and served as a static front-end.
    • Backend functionality (password verification, contact email delivery, protected file access) runs on Lovable Cloud (Supabase) edge functions.
    • Protected client files are stored in private object storage and served through short-lived signed URLs; direct public access is denied.
    • Traffic is fronted by Cloudflare, which provides TLS termination and standard edge protections.

    Data we collect on this site

    • Information you submit through the contact form (name, email, message, and any optional fields you choose to provide). This is used to respond to your enquiry and is delivered by email via our transactional email provider.
    • Standard request metadata (IP address, user agent, referrer) processed by our hosting and CDN providers for delivery, security, and abuse prevention.
    • Analytics and tag-management events when you accept analytics cookies — see the cookie section below.

    For the full data-handling statement, see our Privacy Policy.

    Subprocessors & integrations

    The website relies on the following third parties to operate. Each is used only for the purpose described.

    • Lovable Cloud (Supabase) — backend, edge functions, private storage.
    • Cloudflare — CDN, TLS, and edge protection.
    • Resend — transactional email delivery for contact form submissions.
    • Google reCAPTCHA — bot protection on the contact form.
    • Google Tag Manager & analytics — measurement, loaded only with consent.
    • Calendly — meeting scheduling when you choose to book a call.
    • YouTube — video embeds on selected pages (privacy-enhanced mode where supported).

    Cookies & analytics

    Non-essential cookies (analytics, marketing) are loaded only after you accept them via the cookie banner. You can review or change your choice at any time on the Cookie Preferences page.

    Contact form protections

    • Server-side input validation on all submitted fields.
    • Google reCAPTCHA verification on the server before any message is sent.
    • Generic error responses to avoid leaking internal details.

    Retention & deletion

    Contact-form messages are retained for as long as needed to respond to your enquiry and for reasonable record-keeping afterwards. To request access, export, or deletion of personal information you have submitted, use the Book a Free 30-Min Call button.

    Reporting a security issue

    If you believe you have found a vulnerability in scalexa.ai, please use the Book a Free 30-Min Call button with details and steps to reproduce. Please do not publicly disclose the issue until we have had a reasonable opportunity to investigate and remediate.

    Compliance posture

    Scalexa does not currently advertise independent certifications (such as SOC 2, ISO 27001, HIPAA, or PCI DSS) for this website. For client engagements, the applicable security, privacy, and compliance commitments are defined in the contract for that engagement. Please contact us if you need specific assurances for an evaluation or procurement process.