Security Measures
Version 1.1, last updated 27 August 2026
The technical and organisational measures Skeptiva AB maintains under Article 32 GDPR. Incorporated into the Data Processing Agreement by Section 6.1.
1. Architectural data minimisation
The strongest protection for a customer's email is that most of it never reaches us.
- Parsing, decoding and AI inference happen entirely in the memory of the user's own device.
- Email body content and attachments are transmitted to Skeptiva only as set out at skeptiva.com/data.
- Our infrastructure holds no copy of any mailbox, and the software provides no facility by which we could retrieve one.
- The Admin Portal shows only reported messages and derived analytics, never general correspondence.
- Links flagged by the detection rules are stripped of email addresses and token patterns in query parameters before they leave the device.
- Message subject lines are not read or transmitted by the software outside the Report function.
- The structural layout dump records interface structure only. It contains no message text, subject lines, sender or recipient addresses, attachment contents or folder names.
2. Product security engineering
- The client is written in Rust, a memory-safe language, which substantially reduces the incidence of buffer overflow, use-after-free and related vulnerability classes.
- The client runs under least privilege and relinquishes administrative permissions once installation is complete. It has no general file system access, cannot alter system settings, and does not interact with unrelated applications.
- Release artefacts are code-signed.
- Code review is required before merge to the release branch.
- Dependency scanning and automated vulnerability alerting run on the build pipeline.
3. Encryption
- Data in transit between the software, the Admin Portal and our infrastructure is encrypted using TLS 1.3, and in no case below TLS 1.2.
4. Access control
- Role-based access control on the principle of least privilege. Individual named accounts; shared accounts are not permitted for production.
- Multi-factor authentication is required for all administrative and production access.
- Access to reported messages is restricted to defined security analysis and engineering roles.
- Access is revoked promptly on departure or change of role.
5. Infrastructure and hosting
- Production infrastructure is hosted with Hetzner Online GmbH in Finland (EU), under its ISO/IEC 27001 certified regime for physical security, environmental controls and hardware disposal.
- Analytics (Plausible) and observability (Grafana) are self-hosted on the same EU infrastructure. No third-party analytics or observability provider receives customer data.
- Portal notifications and password reset messages are sent by our own system. No third-party email delivery provider is used.
- No tracking cookies or third-party trackers on our website or Admin Portal.
6. Logging and resilience
- Administrative and production access is logged with actor, action and timestamp. Logs are retained for twelve months and protected against unauthorised modification.
- Backups are taken and stored within the EU/EEA.
- Loss of availability of our hosted services does not interrupt protection on customer endpoints. The software continues to analyse email on the device.
7. Organisational measures
- Confidentiality undertakings for all personnel with access to personal data, surviving the end of their engagement.
- Supplier assessment before engaging any subprocessor.
8. Certifications
Skeptiva does not hold ISO/IEC 27001 certification or a SOC 2 report. We will update this page when that changes. On request we provide a completed standard security questionnaire and this description of our measures.
9. Changes and contact
We may update this page provided the overall level of security is not reduced. Material reductions are notified thirty days in advance under Section 6.2 of the DPA. Questions, or a security questionnaire you need completed: info@skeptiva.com.
Data Processing Agreement Data We Process Security Measures Subprocessors Privacy Policy