Security and trust

How we earn it, in detail.

You are being asked to trust a security product. This page says how it works, what it keeps, who can change what, and where its limits are.

How the scan behaves

The scan is passive. It reads DNS records, fetches your website's front page as any visitor would, completes TLS handshakes with your web and mail servers, and reads public indexes. It does not try passwords, probe ports or attempt a way in. Anything intrusive needs your written permission and is a separate piece of work. A check that cannot finish is recorded as unknown, never as a pass.

Who can change your DMARC policy

One of our engineers, by approving a step. A rule-based reviewer checks each proposed step first, and its verdict is advice. No AI decides anything. The record we host never starts weaker than the one you had, and reject is never applied automatically. Nothing in the partner API can change a policy.

How the platform is protected

How the platform is protected
ControlWhat it means
Content-Security-Policy on every pageNo script runs unless we served it and marked it.
HSTS, no MIME sniffing, a strict referrer policyOn every response.
No server bannerWe switch off the banner our own scanner flags on your site.
Protection against forged requestsEvery action that changes something carries a one-time token.
Rate limitsOn sign-in, sign-up, scans, DNS checks, imports, key creation and more.
Locked-down cookiesSecure, tied to one host, and out of reach of any other site.
Sign-in without passwordsAn emailed link or code, a Microsoft work account, or a passkey.
API keys stored hashedShown once, then never again.
Webhooks that cannot be turned inwardsA destination is checked to be a public address before every delivery.
An audit logEvery consequential action, kept for 24 months.
Partner data kept apartEvery read is scoped to the partner.
Reports kept out of search enginesA report link pasted in public never puts a company's report in search results.
BackupsRegular snapshots, with a copy kept off the server.
Watched from outsideAvailability is tested every 10 minutes from five locations.

What we keep, and for how long

What we keep, and for how long
WhatKept for
A free check run without leaving an email address, and its report link90 days
The record of your address on the network, used to limit how many checks one visitor runs24 hours
The findings of a customer's posture scans90 days
Sign-up attempts, failure reports, the original files of DMARC and TLS reports90 days
DMARC report summaries, sender evidence, posture scans, TLS reports, the audit log24 months
A deleted account's personal dataRemoved at once, and gone from backups within about 7 days

You can ask us to delete your data at any time. The account holder can also delete the account from the portal.

Who else handles your data

Who else handles your data
WhoFor what
Microsoft AzureHosting, backups, sending email
MicrosoftSign-in, when you sign in with a Microsoft work account
CloudflareSits in front of the portal and the scanner; hosts our DNS; receives the DMARC and TLS reports mailed to us (Email Routing)
GoCardlessDirect Debit payments, and the one-off Instant Bank Pay payment for the Full Report
Web3FormsDelivers this website's contact form to our inbox

Where it runs

OuterMark runs on Microsoft Azure in the UK South region. Backups stay in Azure. Cloudflare sits in front of it.

Reporting a vulnerability

Our security.txt is at /.well-known/security.txt, and says where to send a report. We will acknowledge your report, tell you what we find and credit you if you would like. Please give us a reasonable time to fix a problem before you publish it.

What we do not claim

OuterMark holds no ISO 27001 or SOC 2 certificate of its own, and it is not an inbox filter or a penetration test. If we gain a certificate, this page will say which, for what and since when.