Trust & Security
You’re trusting us with every client domain you manage. Here’s exactly how that data is handled.
Every claim below describes ActiScan’s actual, current architecture — not a roadmap, and not a certification we haven’t earned.
Real tenant isolation, not app-layer filtering
ActiScan is multi-tenant by database design: Postgres row-level security policies enforce that one MSP’s session can never read or write another MSP’s domains, scans, or client data — enforced at the database itself, not by an application-layer filter that a bug could bypass. This is stronger isolation than a shared-schema app that relies on every query remembering to filter by tenant.
Nothing changes on your client’s live DNS without your explicit confirmation
When ActiScan can auto-publish a fix (SPF, DMARC, MTA-STS records, across Cloudflare, GoDaddy, Route 53, Azure DNS, Namecheap, and DNSimple), it always shows the exact record it’s about to write and requires a separate confirm step before touching your client’s real DNS. Nothing publishes silently.
Every release goes through a security-focused review before it ships
Before new functionality reaches production, it’s checked specifically for cross-tenant data exposure, credential handling, and access-control gaps — not just whether the feature works. When a review finds a real gap, it gets fixed before release, not logged as a known issue to revisit later.
Secrets and vendor credentials never reach the browser
API keys for every third-party integration — DNS providers, PSA tools, threat intelligence, AI-generated remediation — are read only in server-side code and never shipped to a client browser. Your own DNS and PSA credentials are stored per tenant, isolated by the same row-level security as everything else, never in a shared config any other tenant could read.
Where your data lives
ActiScan runs on Supabase (Postgres) for data and Vercel for hosting — both established infrastructure providers, not a self-hosted server this team also has to secure and patch itself.
This page covers technical architecture only. For data retention, what’s collected, and your legal rights, see ActiScan’s own Privacy Policy and Terms of Service.
Questions about how ActiScan handles a specific security requirement your client has?
Ask us directly →