Trust Center

Security at Securely

Last updated: 16 August 2026

How Securely protects user accounts, scan content, payments and reports — and what we will never ask for.

UK GDPR alignedTLS in transit · provider encryption at restUK-builtPlain-English policies

1. Data encryption

  • All traffic between your device and Securely is encrypted in transit using TLS 1.2+.
  • Data at rest is held on managed database and storage infrastructure provided by Supabase, which applies encryption at rest (AES-256) at the platform level. Securely relies on our providers' encryption controls rather than operating its own encryption hardware.
  • Secrets and API keys are held in our hosting platform's encrypted secret storage, never in source control.
  • We follow good-practice security controls, but Securely holds no formal certification such as ISO 27001 or SOC 2, and no system can be guaranteed 100% secure.

2. Account protection

  • Passwords are hashed with modern, salted algorithms — we never store them in plain text.
  • Sessions use secure, signed tokens with automatic expiry and rotation.
  • Email-based verification protects account recovery flows.
  • Suspicious sign-in activity is logged and rate-limited.

3. Scan content handling

  • Messages, links, transcripts, screenshots and documents you submit are processed solely to return your scam analysis.
  • Content submitted to an AI feature is sent over TLS to OpenAI, which processes it as our provider to generate the result. See our Subprocessors page.
  • Scan history is private to your account, protected by row-level security.
  • You can delete any scan at any time from your dashboard.
  • We do not sell scan content, and we do not use it to train our own or third-party models.

4. Payment security through Stripe

  • All payments are processed by Stripe, a PCI-DSS Level 1 certified payment provider.
  • Securely never sees or stores your full card number, CVC, or banking credentials.
  • Subscription changes and webhooks are signature-verified before being processed.
  • Billing questions: billing@securelyapp.co.uk.

5. Access controls

  • Securely is provided by AE TECHNOLOGIES GROUP LTD (registered in England and Wales, company number 17419062); production access is limited to authorised personnel working on the service.
  • All database access is governed by row-level security policies so users can only access their own data.
  • Administrative actions are logged and audited.
  • Multi-factor authentication is used on production provider accounts.

6. Data deletion

You can delete your account and all associated data at any time from the Account Settings page. See our Account Deletion Policy for the full process and what limited data may be retained for legal compliance.

7. Vulnerability & security reporting

If you believe you've found a security vulnerability in Securely, please report it responsibly to security@securelyapp.co.uk. Please include:

  • A description of the issue and potential impact
  • Steps to reproduce
  • Any proof-of-concept code or screenshots

We acknowledge legitimate reports promptly and ask researchers not to access user data, disrupt service, or publicly disclose issues before we've had a reasonable time to fix them.

8. What Securely will never ask for

Securely will never ask for your banking password, PIN, one-time passcode, or remote access.

If anyone claiming to be from Securely asks for these, it is a scam. Report it immediately to security@securelyapp.co.uk.

Securely staff and Securely emails will never ask you for:

  • Your banking password or online-banking login
  • Your card PIN
  • One-time passcodes from your bank or card issuer
  • Remote access to your computer or phone
  • Your full card number or CVC outside of the Stripe checkout

If you receive a message claiming otherwise, treat it as a scam and forward it to security@securelyapp.co.uk.

Report a security issue

We take every report seriously and respond promptly.

security@securelyapp.co.uk