ScamGuard SOS

Security & Data

For partners, insurers and procurement teams · Last updated: 2 October 2026

ScamGuard SOS is designed to collect as little as possible. There are no accounts and no passwords, and contacts never leave the phone. The only personal data our server holds is a live location, and only while the user is sharing it.

SingaporeServer and database region
No accountsNo logins, passwords or address-book upload
24 h + 7 daysLive-map links expire, then data is deleted
HTTPS onlyAll traffic encrypted in transit

1. What data goes where

DataStoredKept for
Emergency contacts, user's name, alert message, policy number, settingsOn the user's phone only (browser storage)Until the user clears it or uninstalls
Live location, accuracy, battery level and display name (during an SOS)ScamGuard server, SingaporeLink works for up to 24 hours, then the record is deleted within 7 days
Approximate coordinates (country lookup)Sent to BigDataCloud; not stored by ScamGuardNot stored by us
SOS text and WhatsApp messagesSent from the user's own SMS or WhatsApp appNever seen or stored by ScamGuard
Text pasted into the scam checkerAnalysed on the phoneNever uploaded
Usage analyticsUmami (cookieless, no personal data) and Hotjar (personal fields masked)Per each provider's retention settings

2. Insurer assistance channel

3. How the live map is protected

4. Security measures

5. Hosting, uptime and continuity

6. PDPA (Singapore) alignment

7. Certifications and testing

ScamGuard SOS does not currently hold SOC 2 or ISO 27001 certification, and it has not yet had an independent penetration test. On request, we can commission an independent security test and complete a partner's vendor security questionnaire as part of onboarding.

Contact

For security questions, due-diligence requests or to report a vulnerability, email scamguardsos@gmail.com or WhatsApp +65 8887 7041.