Safety by design

A phone call is a real-world side effect. We treat it like one.

SpareScout separates planning, approval, calling, comparison, and any later reservation into distinct decisions.

01

Authenticated operator

Both live endpoints require a private operator credential. A consent checkbox alone never authorizes a call.

02

Authorized recipients

Every live number must exactly match the server-side allowlist and carry a documented consent window.

03

Explicit approval

Browser approval data is time-limited and contains no phone values; execution reloads the authoritative plan privately.

04

AI disclosure

The call task instructs SpareScout to identify itself as an AI assistant collecting a quote for a buyer.

05

Information only

Calls may ask about price, stock, fitment, delivery, and whether a later hold is possible. They cannot reserve, order, pay, purchase, or commit.

06

Masked recipients

The approval screen, browser token, and public history expose no full supplier number. Full numbers remain server-side for authorized execution.

07

Fail-closed live mode

A fixture plan can never become live because configuration changes. Live execution requires a live plan, operator authentication, an allowlist match, and trusted server credentials.

08

Traceable outcomes

Requests, approvals, call runs, confidence, evidence, and normalized quotes are stored together for review.

09

Professional boundaries

SpareScout provides no medical, legal, or financial advice and is never an emergency service. Those topics stop the sourcing workflow and remain with qualified local services or professionals.

Hard boundary

Quote gathering is not purchasing authority.

SpareScout rejects substitute-part acceptance and records missing information as unknown. Selecting an offer in the interface only prepares a separate reservation preview; it does not contact the seller.