Nobody at SpoofDefense can read your email. Ever.
Automated scanners check every message for phishing patterns — then forget it within seconds. No employee, contractor, or AI model trainer ever sees your content.
The Short Version
Our system uses automated software — not people — to check your incoming emails for phishing threats. It works like a security camera that watches for suspicious behavior but doesn't record the footage. No human at Spoof Defense ever sees, reads, or has access to your email content.
How It Works
Think of it like airport security
When you go through airport security, the X-ray machine scans your bag. The machine looks for dangerous items — but it doesn't keep a copy of what's inside your bag. A security officer sees the scan results (“bag is clear” or “bag flagged”), but they never open your bag or read your personal documents inside.
Spoof Defense works the same way:
- 1An email arrives in your inbox
- 2Our automated scanner checks it for threats (like the X-ray machine)
- 3The scanner reports: “safe” or “phishing detected”
- 4The email content is immediately forgotten — never saved, never copied, never stored
What We Keep
Only the scan result — never the email itself:
- Who sent the suspicious email
- Threat level (Low / Medium / High / Critical)
- Type of attack detected
- What action was taken
- When it was scanned
What We Never Keep
Your private communications stay private:
- The email message itself
- Email subject lines (stored only as an irreversible fingerprint)
- File attachments or their contents
- Who you email or your contact list
- Full email headers
Key Assurances
No Human Access
AI Scanning Is Optional and Transparent
Your Data Is Completely Separate
You Are in Control
Frequently Asked Questions
Can Spoof Defense employees read my email?
No. There is no interface, endpoint, or database access to email content. Only automated software processes your email, and it discards the content immediately after scanning.
Is my email stored on your servers?
No. Email content is checked in temporary memory and immediately discarded. Only the threat report (who sent it, what kind of threat) is saved — never the email itself.
What if I enable AI scanning?
The AI is a computer program, not a person. It checks the email and forgets it. The AI provider (Anthropic) does not retain your data. You can disable AI scanning at any time.
Can other companies see my data?
No. Every company's data is completely separate and isolated. There is no way for one customer to access another customer's scan results.
What happens to my data if I cancel?
Your scan history (threat reports only — never email content) can be deleted on request. Since we never store email content, there is nothing to delete on that front.
What happens when I mark an email as safe or phishing?
Your feedback immediately allowlists or blocklists the sender for your organization only. It also helps us improve detection for all customers through anonymized, aggregate pattern analysis. No email content is collected — only your verdict. Feedback is automatically deleted after 90 days.
What compliance standards do you meet?
Our architecture aligns with SOC 2 (access controls, system monitoring) and GDPR (data protection by design, minimal retention). For financial-sector customers (financial, mortgage, insurance, title/escrow), the same zero-retention design supports your GLBA Safeguards obligations. On HIPAA: because we inspect email in-memory and never store body content, attachments, or protected health information, there is nothing for us to retain or expose. If your organization requires a Business Associate Agreement, contact us. HIPAA-covered customers remain responsible for their own policy (for example, that employees do not transmit medical records by email).
Compliance Alignment
Zero-retention architecture: body content and attachments are inspected in-memory and never stored, which supports your HIPAA and GLBA safeguards. If your organization requires a Business Associate Agreement, contact us.