Scrape.Email policy center

Security overview

Scrape.Email applies layered controls to customer identity, private lead delivery, connected email accounts, APIs, payments, and outbound integrations.

Identity and authorization

Passwords are stored as salted scrypt hashes. Sessions use signed, HTTP-only cookies. Customer records are filtered by authenticated account ID. API keys are scoped, displayed once, stored as keyed digests, and revocable. Webhook signing secrets and SMTP credentials are encrypted at rest and never returned after creation.

Network and browser protections

Production traffic uses HTTPS and HSTS. Responses include a Content Security Policy with clickjacking restrictions, MIME-sniffing protection, a restrictive Permissions Policy, and a strict-origin referrer policy. SMTP, IMAP, webhook, and website-ingestion features reject loopback, private, link-local, and embedded-credential destinations and require valid transport certificates.

Data separation and delivery

The source lead archive remains in private, versioned object storage. Only contacts explicitly revealed or exported are copied into the authenticated customer's saved-lead workspace. Preview requests expose totals rather than contact rows. Credits are reserved before delivery and refunded if delivery or durable account-scoped saving fails.

Administrative customer-workspace access requires an active administrator session, uses a separate signed return session, displays a persistent access banner, and records access and account mutations in the administrative audit log.

Email and payment safeguards

SMTP sending accepts one recipient per request, requires explicit user approval, and records delivery attempts. Inbox synchronization is read-only, incremental, bounded, and does not mark, move, or delete provider messages. Plan activation occurs only after signed provider webhooks pass identity, ledger, amount, currency, and status checks; browser redirects are not payment proof.

Incident reporting

Report suspected vulnerabilities or account compromise to waconzy@live.com. Include reproduction details but no passwords, API keys, webhook secrets, SMTP credentials, or unnecessary personal data. Active security reports are acknowledged within 24 hours, and confirmed personal-data breaches are communicated under the timeline in the Data Processing Addendum.

Effective and last updated: September 11, 2026. Dv8 Media Publishing operates Scrape.Email. Contact waconzy@live.com for legal, privacy, billing, or support requests.