Trust Center
Security, compliance, and data handling at SpoofSentry. We build enterprise-grade controls so you can trust us with your email security.
Security Controls
Encryption
- TLS 1.3 for all data in transit
- AES-256 encryption at rest (GCP managed keys)
- Fernet encryption for sensitive fields
- Channel binding on database connections
Authentication
- OIDC and SAML 2.0 SSO
- SCIM 2.0 automated provisioning
- MFA / TOTP with recovery codes
- WebAuthn / passkey support
- Magic link passwordless login
- IP allowlist per tenant
Authorization
- 91 RBAC permissions across 8 roles and 28 resource types
- 90 row-level security (RLS) policies
- API key scoping with rate limits
- Privileged access management (PAM)
- Two-person approval for critical actions
Audit & Monitoring
- 440+ audit event types
- Tamper-evident audit trail
- SIEM integration (Splunk, Elastic, Sentinel, Datadog)
- Real-time security event forwarding
- Exportable audit logs for compliance
Tenant Isolation
- Row-level security at database layer
- Tenant-scoped API keys and sessions
- Cross-tenant protection middleware
- VPC-scoped network egress
- Separate MSSP/customer RBAC roles
Infrastructure
- Google Cloud Run (serverless, auto-scaling)
- Cloudflare WAF with OWASP ruleset
- DDoS protection at edge
- Non-root containers with restricted writable paths (limited to /tmp)
- Secret Manager for all credentials
- Automated secret rotation monitoring
Compliance Frameworks
SpoofSentry generates compliance evidence bundles and control mappings for these frameworks. Enterprise customers can export evidence directly from the platform. These are internal evidence packages — independent third-party audit reports are listed separately where available.
Data Handling
Data Residency
SpoofSentry currently operates in the US region. The table below shows where each data class is stored and what is configurable.
| Data Class | Current Region | Configurable |
|---|---|---|
| Application database (PostgreSQL) | US (Neon us-east-1) | No |
| Compute & API | US (GCP us-central1) | No |
| Report & evidence storage | US (GCS us-central1) | No |
| CDN & WAF edge cache | Global (Cloudflare) | N/A — no PII cached |
| Payment data | US (Stripe) | No |
| Transactional email | AU / US (ZeptoMail) | No |
| AI processing (optional) | US (Anthropic) | Opt-out available |
Multi-region deployment is not currently available. For specific data residency requirements, contact [email protected].
Subprocessors
| Provider | Purpose | Location |
|---|---|---|
| Google Cloud Platform | Application hosting, compute, storage | US (us-central1) |
| Neon | PostgreSQL database | US (us-east-1) |
| Cloudflare | CDN, DDoS protection, WAF | Global edge |
| Stripe | Payment processing | US |
| ZeptoMail (Zoho) | Transactional email delivery | AU / US |
| Anthropic | AI-powered sender classification (optional) | US |
Last updated: April 2026. Changes to this list are communicated to affected customers 30 days in advance.
Security Contact
To report a vulnerability or request security documentation:
[email protected]