Trust & compliance
Everything you need to evaluate PhishFence in one place: privacy, terms, security posture, and sub-processors. Procurement teams: this is the URL you want.
Operating entity: MAJUVO LLC · California, United States. PhishFence is a MAJUVO product.
Documents
Sub-processors
Every third party that touches customer data is listed here. Customers will be notified at least 30 days before a new sub-processor is added.
| Sub-processor | Purpose | Data shared | Region |
|---|---|---|---|
| Google Cloud Platform | Application hosting (Cloud Run, Cloud SQL, Cloud Storage, Cloud Logging, Cloud Scheduler, Secret Manager) | All customer data at rest and in transit through the application tier | United States |
| Stripe | Payment processing & subscription management | Billing email, subscription & invoice metadata, last 4 digits of payment method (card data handled by Stripe, never seen by PhishFence) | United States |
| Resend | Transactional email delivery (account verification, password reset, alert notifications) | Recipient email address & the message body of system mail we send | United States |
| Sentry | Application error monitoring | Stack traces and request metadata, scrubbed of PII before transmission | United States |
| PostHog | Product analytics and masked session replay on public marketing pages only (never on authenticated or admin pages) | Pseudonymous device & session identifier, page path and referrer without query string, performance timings; no account identifiers, email addresses, or form input | United States |
| Cloudflare | TLS termination for hosted MTA-STS custom hostnames; optional DNS management for customers who connect a Cloudflare-hosted domain | The relevant customer domain name and, for connected DNS accounts, the DNS records needed to publish records on the customer's behalf; no phishfence.io application traffic or database data | Global edge network |
| AWS Route 53 | Authoritative DNS for phishfence.io | No customer data. DNS records for our domain only | United States |
| Anthropic | LLM-backed analysis features (DMARC assistant, beta) | Only the specific DMARC record / report excerpt sent for the requested analysis; no auth credentials or persistent identifiers | United States |
Last updated 2026-09-04. Subscribe to security@phishfence.io for change notifications.
Vulnerability reporting
Send vulnerability reports to security@phishfence.io. Coordinates are published per RFC 9116 at /.well-known/security.txt. Full disclosure policy and SLAs on the Security page.
Procurement reviewing PhishFence?
DPAs, security questionnaires, and custom MSAs all get same-week turnaround. The fastest way to close out your review is to email the trust desk directly.