How the AI Works
When you submit something for investigation — a URL, a phone number, a job offer, a business name — this is what actually happens:
Most scam-detection tools
Query a database of previously reported scams. If the URL, phone number, or business name isn't already on the list — it passes. Scammers know this. New operations stay off the lists long enough to take victims.
How Scamanot works
The AI reasons about what you submitted — its tactics, language, structure, and pressure signals. It doesn't look the scammer up. It asks: does this thing behave like a scam? That's why it can catch brand-new operations that have never been reported anywhere.
Your submission goes to our server — not the AI directly
It travels over an encrypted HTTPS connection to a Cloudflare Worker at api.scamanot.com. Your browser has no direct line to the AI. That's intentional.
The Worker sends it to Claude AI (by Anthropic)
Our server-side Worker forwards your input to Claude, Anthropic's AI model, using a structured prompt specific to the type of scam check you've requested. The API key is stored in Cloudflare's encrypted environment — it never reaches your browser.
The AI investigates — it doesn't look things up
Claude knows how scams are built — the pressure patterns, the language, the way they're structured to get past your gut feeling. So it doesn't need a name on a list. It reads what you submitted and asks whether it behaves like a scam. A brand-new operation, one that's never been reported anywhere, can still fail that test. The tactics aren't new, even when the name is.
The report comes back to you. We don't keep a copy.
The analysis goes straight to your screen. We don't log what you submitted or what the AI found. Free accounts get session-only results; paid subscribers can save their report history if they want it.
Data — What We Store & What We Don't
The safest data is data we never collected. We keep the minimum the service needs to function and nothing else.
What We Store
- Your account email address — for login and report delivery only
- Your hashed password — never stored in readable form, ever
- Subscription tier and billing status — for access control only
- Report history — only for paid subscribers who explicitly opt in
- Anonymised, aggregate usage metrics — no individual tracking
What We Do Not Store
- Your search queries — URLs, names, or text you submit for analysis
- AI-generated report content — not permanently logged on our end
- Payment details — Stripe handles all transactions; we never see your card
- IP addresses — beyond temporary server security logs
- Browser fingerprints, device data, or behavioural tracking
- Any data sold to third parties — ever, under any circumstances
All payment processing is handled exclusively by Stripe. No credit card data ever touches Scamanot's servers. Stripe's webhook notifications to us contain only subscription status — nothing financial.
What Our Tools Cannot Tell You
We'd rather tell you what we can't do than have you find out the hard way. Here's what Scamanot won't tell you:
Guarantee safety
A low-risk score means the available signals look clean — it does not guarantee the entity is legitimate. New scams evolve faster than any dataset.
Access real-time databases
Our AI reasons from patterns and training data, not live law enforcement, banking, or fraud registries. It cannot look up a phone number in a live blocklist in real time.
Provide legal advice
Scamanot is an investigative aid, not a legal service. Nothing on this platform constitutes legal counsel. If you've been defrauded, contact your local authorities.
Verify identities with certainty
We can flag the red flags. We can't confirm someone is who they say they are — that needs official verification we don't have access to.
Predict future scam risk
A clean result is a snapshot, not a clearance. Something that looks fine today can turn. We're showing you what the signals say right now.
Replace human judgement
The report informs your call. It doesn't make it. If something still feels wrong after a clean result, that feeling is worth listening to.
Security Infrastructure
People who use Scamanot are often already worried about something. We don't take that lightly. Here's what's in place:
Cloudflare WAF + DDoS protection
Every request passes through Cloudflare's Web Application Firewall. Common attack patterns are blocked before they reach our application.
A+ Content Security Policy
Our CSP grade is A+. Third-party scripts that could compromise user data are not permitted — which is also why we don't run Google AdSense.
DNSSEC + Domain Lock
DNSSEC prevents DNS spoofing. Domain lock prevents unauthorised transfers. Both are active on scamanot.com.
Rate limiting on all endpoints
All API endpoints are rate-limited per user per hour to prevent abuse, scraping, and denial-of-service attempts.
We Find The Truth. We Never Expose Yours.
That's not a tagline. It's the reason every decision on this platform gets made the way it does — including the ones that would have been easier to skip.
Questions about this policy? support@scamanot.com