Trust & compliance

Everything you need to evaluate PhishFence in one place — privacy, terms, security posture, sub-processors, and our compliance roadmap. Procurement teams: this is the URL you want.

Documents

Data Processing Addendum (DPA)
Custom-issued for paid customers on request. Same-week turnaround typical.
On request
Request DPA →
Security questionnaires (SIG, CAIQ, custom)
Same-week turnaround from the founder given solo-operator model. Send whatever format your team uses.
On request
Send questionnaire →

Sub-processors

Every third party that touches customer data is listed here. Customers will be notified at least 30 days before a new sub-processor is added.

Sub-processor Purpose Data shared Region
Google Cloud PlatformApplication hosting (Cloud Run, Cloud SQL, Cloud Storage, Cloud Logging, Cloud Scheduler, Secret Manager)All customer data at rest and in transit through the application tierUnited States
StripePayment processing & subscription managementBilling email, subscription & invoice metadata, last 4 digits of payment method (card data handled by Stripe, never seen by PhishFence)United States
ResendTransactional email delivery (account verification, password reset, alert notifications)Recipient email address & the message body of system mail we sendUnited States
SentryApplication error monitoringStack traces and request metadata, scrubbed of PII before transmissionUnited States
CloudflareCDN, DDoS protection, Turnstile bot challenge on signupRequest metadata (IP, user agent, headers); no application database dataGlobal edge network
AWS Route 53Authoritative DNS for phishfence.ioNo customer data — DNS records for our domain onlyUnited States
AnthropicLLM-backed analysis features (DMARC assistant)Only the specific DMARC record / report excerpt sent for the requested analysis; no auth credentials or persistent identifiersUnited States

Last updated 2026-05-15. Subscribe to trust@phishfence.io for change notifications.

Compliance roadmap

What we hold today, what we're working toward, and what we don't plan to pursue. See /security for the long-form context.

  1. Today
    GDPR-aligned posture

    Data deletion implemented end-to-end; sub-processors disclosed; EU-resident customers treated as data subjects. No formal certification yet.

  2. Q4 2026
    Third-party penetration test

    Targeted Q4 2026. Executive summary published publicly; full report shared under NDA.

  3. 2027
    SOC 2 Type 1

    Once revenue and customer count justify the audit cost (~$15–25K plus ongoing).

  4. 2027+
    SOC 2 Type 2 & ISO 27001

    Follow on from Type 1 by the standard 6-month observation period.

  5. Not on roadmap
    HIPAA, FedRAMP

    PhishFence is not designed for protected health information or US Federal Government use.

Status & uptime

All systems operational

Status page at status.phishfence.io is being stood up. Until it goes live, incident communication goes via email to the address of record on each affected account. For service-level questions in the meantime: support@phishfence.io.

Vulnerability reporting

Send vulnerability reports to security@phishfence.io. Coordinates are published per RFC 9116 at /.well-known/security.txt. Full disclosure policy and SLAs on the Security page.

Procurement reviewing PhishFence?

DPAs, security questionnaires, and custom MSAs all get same-week turnaround given the solo-operator model. The fastest way to close out your review is to email the founder directly.