Trust & Security

    Your DMARC data is sensitive. Here's how we protect it — in plain language, not legalese.

    Tenant Separation

    Every organisation's data is fully isolated. Row-level security policies ensure that users can only access data belonging to their own organisation. There is no shared data layer between tenants.

    Report Storage

    DMARC reports are stored encrypted at rest using AES-256. Data is hosted in SOC 2-compliant infrastructure with automated backups and point-in-time recovery.

    Webhook Verification

    All incoming DMARC report webhooks are verified for authenticity before processing. Invalid or tampered payloads are rejected and logged for audit.

    Retention Controls

    You control how long your data is retained. Each plan includes a defined retention period, and data is automatically purged when no longer needed. Enterprise customers can define custom retention policies.

    Audit Logging

    All significant actions — user logins, configuration changes, policy updates, and data exports — are logged with timestamps and user identity. Audit logs are available to organisation admins.

    Operational Monitoring

    Our platform is continuously monitored for uptime, performance, and security anomalies. We maintain an incident response process with defined escalation procedures and post-incident reviews.