ActiScan

Privacy Policy

Last updated September 22, 2026

This policy explains what Securafy Inc. collects through ActiScan (actiscan.ai), why, and what you can do about it. It covers three different groups of people, because ActiScan is used differently by each: account holders (you, if you signed up), your teammates you invite, and — if you enable the embeddable scan widget — visitors to your own website who use it. See Terms of Service for the contract governing use of the Service itself.

1. What we collect

Account data: your email, a hashed password (we never see or store it in plain text), and your organization name and branding (logo, color, contact info) if you set it.

Domain and scan data: the domains you add and the public DNS records our checks read (SPF, DMARC, DKIM, BIMI, MTA-STS), plus the scores, grades, and findings we compute from them. If you manually upload or configure automatic receipt of DMARC/failure/TLS reports, those reports — which can include sending-server IP addresses and limited message metadata, never message content — are stored and parsed.

Optional connections: if you connect a DNS provider (Cloudflare, GoDaddy), CRM (HubSpot or a webhook URL), PSA (ConnectWise, Autotask, HaloPSA), or a sending mailbox for inbox-placement testing (Section 4), we store the credential or token you provide so the Service can act on your instructions (Terms Section 5). We never use these connections except when you trigger the specific action they enable.

Billing data: handled by Stripe, Inc. — we receive and store only a subscription status and a Stripe customer reference, never your card number.

Embed widget visitors: if you enable the embeddable scan widget on your own site, a visitor who requests the full report submits their name, email, and optionally company, job title, and phone. You are the data controller for this information — we process and store it on your behalf, hand it back to you on your Leads page, and forward it to your connected CRM if you've set one up. We don't use it for our own marketing.

Usage data: ordinary web server logs (IP address, timestamp, requested URL) and, once enabled, error/performance data via Sentry.

2. How we use it

  • To operate the Service: run scans, render your dashboard and reports, enforce plan limits, process billing
  • To generate AI-written remediation text and Help-assistant answers (Section 3) — never to train a model, ours or anyone else's
  • To send transactional email: signup confirmation, password reset, scan-finding alerts, and (Terms Section 3) trial-ending and billing notices
  • To detect abuse and keep the Service secure and available

3. Who we share it with

We don't sell personal data. We share it only with the sub-processors that run the Service, each bound by their own data-processing terms:

  • Supabase — database, authentication, and file storage
  • Vercel — application hosting
  • Stripe — payment processing
  • Resend — outbound transactional email and, where configured, inbound DMARC/TLS report receipt
  • Anthropic — generates AI remediation text and Help-assistant chat answers from scan/check data and your questions; never receives your account password or payment details
  • Google (Safe Browsing API) — checks a submitted URL against known-phishing lists, only when you use the phishing-link tool
  • Any CRM, PSA, or DNS provider you personally choose to connect (Section 1)

We may also disclose data if required by law, subpoena, or to protect the rights, property, or safety of Securafy, our users, or the public.

4. Google user data (Gmail sending connection)

ActiScan's inbox-placement testing lets you connect a Google Workspace or Gmail mailbox on a domain you manage, so the Service can send a test message from that domain to our seed mailboxes and measure where it lands — inbox, spam, or undelivered. This section describes exactly what that connection grants and how we handle it. It applies only if you choose to connect a Google mailbox; nothing here happens otherwise.

The scope we request: gmail.send, and nothing else. This is the narrowest Gmail scope Google offers — it permits sending a message on your behalf and grants no other access. It does notlet us read, search, download, modify, or delete anything in your mailbox, and we never attempt to. We do not read your inbox, sent mail, drafts, contacts, or labels.

What we store: the connected mailbox's email address and an OAuth refresh token, encrypted at rest and scoped to the tenant and domain you connected it to. The token exists for one purpose: so a placement test you scheduled or triggered can send its test message.

What we do with it: send the test message you asked for. The placement result is measured at our seed mailboxes — the receiving side — not by inspecting your Google account. We do not use Google user data for advertising, we do not sell it, and we do not use it to train any AI or machine-learning model (ours or anyone else's). We do not transfer it to anyone except: to provide this feature, and only with your consent; for security purposes, such as investigating abuse; to comply with applicable law; or as part of a merger, acquisition, or sale of assets, and then only after obtaining your explicit prior consent. No Securafy employee reads Google user data unless you have given affirmative agreement for us to view the specific data in question (for example, when you ask us to investigate a support issue), it is necessary for security purposes such as investigating a bug or abuse, it is necessary to comply with applicable law, or the data is aggregated and used for internal operations in accordance with applicable privacy law.

Limited Use commitment: ActiScan's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Revoking access: disconnect the mailbox from your ActiScan dashboard at any time, which deletes the stored refresh token. You can also revoke ActiScan's access directly from your Google Account at myaccount.google.com/permissions. Either action stops all future test sends from that mailbox.

5. Data retention

We retain account and scan data for as long as your account is active, plus a reasonable period after cancellation in case you resubscribe, then delete it. You can request earlier deletion (Section 7). Server logs are retained for a limited period for security and troubleshooting, then automatically purged.

6. Security

Data is encrypted in transit (TLS) and at rest via our infrastructure providers. Access to production data is limited to what's needed to operate the Service. No method of transmission or storage is 100% secure, and we can't guarantee absolute security — see Terms Section 7.

7. Your rights and choices

You can access, correct, export, or delete most of your own account data directly from the dashboard. To request deletion of data we can't self-serve (e.g. after account closure) or to exercise a right your local law provides (access, correction, deletion, portability, or objection to processing), email privacy@securafy.com. If you're a visitor whose data was submitted through someone else's embedded ActiScan widget, contact that website's owner first, since they control that data — we'll assist them with a legitimate request.

8. Children's privacy

The Service is a B2B product for businesses monitoring their own or their clients' domains. It's not directed to children, and we don't knowingly collect data from anyone under 16.

9. International data transfer

Our infrastructure providers may process data in the United States and other countries. If you're accessing the Service from outside the U.S., you understand your data may be transferred to and processed in a country with different data-protection laws than your own.

10. Changes to this policy

We may update this policy as the Service evolves. For material changes, we'll notify active subscribers by email at least 15 days before the change takes effect.

11. Contact

Questions about this policy or a privacy request: privacy@securafy.com.