Security Overview
Last updated September 25, 2026
This page describes how Alesian Security protects the Service and the data customers trust us with. We describe only what we do today. Where something is planned, we say so.
About us
Alesian Security LLC is a small Colorado company. That shapes our security model: very few people have access to production, every change is made by someone who knows the whole system, and we avoid tools that would put customer data in more places than necessary.
What we handle
| Product | Data | Personal data? |
|---|---|---|
| Lookalike monitoring | Names you watch; public DNS, WHOIS, IP ownership and blocklist data about lookalike domains | Occasionally, where a registrar publishes registrant details |
| Mail defense | DMARC aggregate and failure reports | Sending server addresses; failure reports can include message headers with sender and recipient addresses |
| Accounts and billing | Users, roles, organization and billing contact | Yes |
We do not ask for, and the Service is not designed to hold, passwords to your systems, card numbers or sensitive personal data.
Infrastructure
- Hosted on Amazon Web Services in the United States (us-east-1).
- Origin servers accept traffic only from our content delivery network.
- Application secrets are kept in a managed secrets store, not in source code.
- Automated backups, each expiring 30 days after creation.
Encryption
- In transit: all traffic to the Service uses TLS 1.2 or later.
- At rest: database storage, volumes and backups are encrypted with AES-256, using AWS-managed encryption.
Access control
Inside the Service
- Passwords are hashed with Argon2id. Recovery codes are stored only as hashes.
- A second sign-in factor is available to every user, and administrators can require it for their whole account.
- A block request can only be made for names that imitate a domain the customer has verified, by an email sent from an administrative address at that domain.
- Roles (administrator, member, viewer, billing) limit what each user can see and do.
- Each customer's data is separated from every other customer's in the application.
- Sessions expire after 12 hours. Repeated failed sign-ins are recorded and limited.
- Account actions are written to an audit log.
For Alesian personnel
- Production access is limited to one named person. We do not use shared credentials.
- A second factor is required on our cloud, source code, email and payment accounts.
- Service roles in AWS follow least privilege.
- We access customer data only to operate and support the Service, investigate a problem, or respond to a legal requirement.
Third-party connections
- DMARC reports: aggregate and failure (forensic) reports are received at a dedicated mailbox and parsed automatically. Failure reports can contain message headers. Message bodies and attachments are discarded on receipt, and only the headers are kept.
- Blocklist operators: receive only a domain name, the evidence about it, and (unless otherwise agreed) your organization's name, and only when you request a block that we approve.
- Payments: handled by Stripe. We never see full card numbers.
- Website analytics: Cabin counts page views without cookies or identifiers, and does not store visitors' IP addresses.
A current list of subprocessors is at alesiansecurity.com/legal/subprocessors.
Development
- Changes are tested before deployment.
- Dependencies are kept up to date.
- We follow common secure-coding practice, including the OWASP Top 10.
Data retention and deletion
- Failed sign-ins are deleted after 1 day; expired sessions after 7 days.
- DMARC reports are kept for the subscription plus 90 days.
- If a subscription lapses, we keep the account for 90 days in case of late renewal, then delete it within 30 days; a customer can ask for deletion sooner. Backups expire within about 60 days.
- Public DNS and WHOIS history is kept long-term as a historical record. It is information registrars publish, and most registrants' details are replaced by a registrar's privacy service.
- Customers can request an export or earlier deletion by emailing admin@alesiansecurity.com.
Incident response
We have a written procedure for detecting, containing and investigating security incidents. If an incident affects customer personal data, we notify affected customers without undue delay and within 72 hours of becoming aware of it.
Not yet in place
We think it is better to say this plainly than to leave you guessing. Alesian does not currently have: a SOC 2 report or ISO 27001 certification; an independent penetration test; a SIEM; or formal background checks. We are happy to answer a reasonable security questionnaire.
Responsible disclosure
If you believe you have found a vulnerability, please email admin@alesiansecurity.com (see /.well-known/security.txt). Please give us reasonable time to fix it before disclosing, and do not access other customers' data, degrade the Service, or test by social engineering. We will not pursue legal action against good-faith research that follows these guidelines.
Contact
Security questions: admin@alesiansecurity.com.