Trust Center

Security at Securely

Last updated: 17 June 2026

How Securely protects user accounts, scan content, payments and reports — and what we will never ask for.

UK GDPR alignedEncrypted in transit & at restUK-builtPlain-English policies

1. Data encryption

  • All traffic between your device and Securely is encrypted in transit using TLS 1.2+.
  • All data at rest — accounts, scan history, voice analysis, reports — is encrypted using industry-standard AES-256.
  • Secrets and API keys are stored in encrypted vaults, never in source control.

2. Account protection

  • Passwords are hashed with modern, salted algorithms — we never store them in plain text.
  • Sessions use secure, signed tokens with automatic expiry and rotation.
  • Email-based verification protects account recovery flows.
  • Suspicious sign-in activity is logged and rate-limited.

3. Scan content handling

  • Messages, links and voice transcripts you submit are processed solely to return your scam analysis.
  • Scan history is private to your account, protected by row-level security.
  • You can delete any scan at any time from your dashboard.
  • We do not sell scan content and do not use it to train third-party models.

4. Payment security through Stripe

  • All payments are processed by Stripe, a PCI-DSS Level 1 certified payment provider.
  • Securely never sees or stores your full card number, CVC, or banking credentials.
  • Subscription changes and webhooks are signature-verified before being processed.
  • Billing questions: billing@securelyapp.co.uk.

5. Access controls

  • Production access is limited to a small number of authorised engineers.
  • All database access is governed by row-level security policies so users can only access their own data.
  • Administrative actions are logged and audited.
  • Staff use multi-factor authentication on all production systems.

6. Data deletion

You can delete your account and all associated data at any time from the Account Settings page. See our Account Deletion Policy for the full process and what limited data may be retained for legal compliance.

7. Vulnerability & security reporting

If you believe you've found a security vulnerability in Securely, please report it responsibly to security@securelyapp.co.uk. Please include:

  • A description of the issue and potential impact
  • Steps to reproduce
  • Any proof-of-concept code or screenshots

We acknowledge legitimate reports promptly and ask researchers not to access user data, disrupt service, or publicly disclose issues before we've had a reasonable time to fix them.

8. What Securely will never ask for

Securely will never ask for your banking password, PIN, one-time passcode, or remote access.

If anyone claiming to be from Securely asks for these, it is a scam. Report it immediately to security@securelyapp.co.uk.

Securely staff and Securely emails will never ask you for:

  • Your banking password or online-banking login
  • Your card PIN
  • One-time passcodes from your bank or card issuer
  • Remote access to your computer or phone
  • Your full card number or CVC outside of the Stripe checkout

If you receive a message claiming otherwise, treat it as a scam and forward it to security@securelyapp.co.uk.

Report a security issue

We take every report seriously and respond promptly.

security@securelyapp.co.uk