Data Protection

Nobody at SpoofDefense can read your email. Ever.

Automated scanners check every message for phishing patterns — then forget it within seconds. No employee, contractor, or AI model trainer ever sees your content.

The Short Version

Our system uses automated software — not people — to check your incoming emails for phishing threats. It works like a security camera that watches for suspicious behavior but doesn't record the footage. No human at Spoof Defense ever sees, reads, or has access to your email content.

How It Works

Think of it like airport security

When you go through airport security, the X-ray machine scans your bag. The machine looks for dangerous items — but it doesn't keep a copy of what's inside your bag. A security officer sees the scan results (“bag is clear” or “bag flagged”), but they never open your bag or read your personal documents inside.

Spoof Defense works the same way:

  1. 1An email arrives in your inbox
  2. 2Our automated scanner checks it for threats (like the X-ray machine)
  3. 3The scanner reports: “safe” or “phishing detected”
  4. 4The email content is immediately forgotten — never saved, never copied, never stored

What We Keep

Only the scan result — never the email itself:

  • Who sent the suspicious email
  • Threat level (Low / Medium / High / Critical)
  • Type of attack detected
  • What action was taken
  • When it was scanned

What We Never Keep

Your private communications stay private:

  • The email message itself
  • Email subject lines (stored only as an irreversible fingerprint)
  • File attachments or their contents
  • Who you email or your contact list
  • Full email headers

Key Assurances

No Human Access

There is no screen, tool, or system that lets any Spoof Defense employee view your email content. Even our system administrators cannot access it because it simply isn't stored anywhere to access. Email content passes through our scanner's temporary memory and is immediately discarded — like water flowing through a pipe.

AI Scanning Is Optional and Transparent

If you enable AI-powered threat detection, our AI reviewer (a computer program, not a person) analyzes the email for sophisticated attacks. The AI provider does not keep your email content — it's processed and immediately deleted. You can turn AI scanning on or off at any time from your dashboard.

Your Data Is Completely Separate

Think of it like separate safe deposit boxes at a bank. Each company has their own box, and no one else has the key. Your scan results are invisible to other customers, and their results are invisible to you. Anonymized, aggregate detection patterns (not individual data) may be used to improve detection accuracy for all customers. No individual company data is shared.

You Are in Control

You can disconnect your email at any time. You can turn AI scanning on or off. You can request deletion of your scan history. Your data, your choice.

Frequently Asked Questions

Can Spoof Defense employees read my email?

No. There is no interface, endpoint, or database access to email content. Only automated software processes your email, and it discards the content immediately after scanning.

Is my email stored on your servers?

No. Email content is checked in temporary memory and immediately discarded. Only the threat report (who sent it, what kind of threat) is saved — never the email itself.

What if I enable AI scanning?

The AI is a computer program, not a person. It checks the email and forgets it. The AI provider (Anthropic) does not retain your data. You can disable AI scanning at any time.

Can other companies see my data?

No. Every company's data is completely separate and isolated. There is no way for one customer to access another customer's scan results.

What happens to my data if I cancel?

Your scan history (threat reports only — never email content) can be deleted on request. Since we never store email content, there is nothing to delete on that front.

What happens when I mark an email as safe or phishing?

Your feedback immediately allowlists or blocklists the sender for your organization only. It also helps us improve detection for all customers through anonymized, aggregate pattern analysis. No email content is collected — only your verdict. Feedback is automatically deleted after 90 days.

What compliance standards do you meet?

Our architecture aligns with SOC 2 (access controls, system monitoring) and GDPR (data protection by design, minimal retention). For financial-sector customers (financial, mortgage, insurance, title/escrow), the same zero-retention design supports your GLBA Safeguards obligations. On HIPAA: because we inspect email in-memory and never store body content, attachments, or protected health information, there is nothing for us to retain or expose. If your organization requires a Business Associate Agreement, contact us. HIPAA-covered customers remain responsible for their own policy (for example, that employees do not transmit medical records by email).

Compliance Alignment

SOC 2-aligned
GDPR
GLBA
HIPAA-aligned

Zero-retention architecture: body content and attachments are inspected in-memory and never stored, which supports your HIPAA and GLBA safeguards. If your organization requires a Business Associate Agreement, contact us.