Trust & Security
What ActiScan does with your data, in plain language – every claim here traces to our Terms and Privacy Policy.
We don't read your email
ActiScan reads public DNS records – the same records anyone can look up with dig or nslookup – and, if you configure it, the aggregate/failure/TLS reports your own mail providers send. It never accesses, reads, or transmits the content of your or your clients' email. The one exception is the Email Header Analyzer tool, where you paste in raw headers for a one-off check – that's content you submitted directly, not something ActiScan pulled from a mailbox.
Multi-tenant, isolated by design
ActiScan is built multi-tenant from the ground up, not a shared login with filters bolted on. Every tenant's domains, scan results, and team data are isolated at the database layer via row-level security – one tenant's data isn't reachable by another tenant's account, by construction, not by application-code discipline alone. Per-tenant CRM and PSA credentials (HubSpot tokens, ConnectWise/HaloPSA keys) are stored the same way – scoped per tenant, never in shared config.
Where your data lives
Data is encrypted in transit (TLS) and at rest via our infrastructure providers. Access to production data is limited to what's needed to operate the Service. We share data only with the sub-processors that run the Service, each bound by their own data-processing terms:
Supabase
Database, authentication, and file storage
Vercel
Application hosting
Stripe
Payment processing – we never see your card number
Resend
Outbound email and, where configured, inbound DMARC/TLS report receipt
Anthropic
AI remediation text and Help-assistant answers – never your password or payment details
Google (Safe Browsing API)
Checks a submitted URL against known-phishing lists, only when you use the phishing-link tool
What we don't do
- •Read or transmit the content of your or your clients' email – only public DNS records and the aggregate/failure/TLS report metadata you configure
- •Sell personal data, to anyone, ever
- •Train any AI model – ours or a vendor's – on your data
- •Touch your DNS, CRM, or PSA without an explicit action you took
The company behind it
ActiScan is built and operated by Securafy Inc., an Ohio corporation. Questions about how we handle data: privacy@securafy.com. Questions about the Terms: legal@securafy.com.