ActiScan

Trust & Security

What ActiScan does with your data, in plain language – every claim here traces to our Terms and Privacy Policy.

We don't read your email

ActiScan reads public DNS records – the same records anyone can look up with dig or nslookup – and, if you configure it, the aggregate/failure/TLS reports your own mail providers send. It never accesses, reads, or transmits the content of your or your clients' email. The one exception is the Email Header Analyzer tool, where you paste in raw headers for a one-off check – that's content you submitted directly, not something ActiScan pulled from a mailbox.

Multi-tenant, isolated by design

ActiScan is built multi-tenant from the ground up, not a shared login with filters bolted on. Every tenant's domains, scan results, and team data are isolated at the database layer via row-level security – one tenant's data isn't reachable by another tenant's account, by construction, not by application-code discipline alone. Per-tenant CRM and PSA credentials (HubSpot tokens, ConnectWise/HaloPSA keys) are stored the same way – scoped per tenant, never in shared config.

Where your data lives

Data is encrypted in transit (TLS) and at rest via our infrastructure providers. Access to production data is limited to what's needed to operate the Service. We share data only with the sub-processors that run the Service, each bound by their own data-processing terms:

Supabase

Database, authentication, and file storage

Vercel

Application hosting

Stripe

Payment processing – we never see your card number

Resend

Outbound email and, where configured, inbound DMARC/TLS report receipt

Anthropic

AI remediation text and Help-assistant answers – never your password or payment details

Google (Safe Browsing API)

Checks a submitted URL against known-phishing lists, only when you use the phishing-link tool

What we don't do

  • •Read or transmit the content of your or your clients' email – only public DNS records and the aggregate/failure/TLS report metadata you configure
  • •Sell personal data, to anyone, ever
  • •Train any AI model – ours or a vendor's – on your data
  • •Touch your DNS, CRM, or PSA without an explicit action you took

The company behind it

ActiScan is built and operated by Securafy Inc., an Ohio corporation. Questions about how we handle data: privacy@securafy.com. Questions about the Terms: legal@securafy.com.

Read the full legal terms