Data minimisation
We store none of your data
Your database and your files are never sent to us and never leave your information system.
The only things retained on our infrastructure are the inbound emails and SMS received by the fictitious accounts, when their sender is not on the allowlist you define. In other words, we retain only messages that originate outside your organisation and are potentially unlawful, precisely the elements that make up the evidence being sought.
What this means for your compliance. The messages retained contain, by construction, no business data belonging to your organisation. Your exposure surface at a third party is therefore nil: there is nothing on our side that could constitute a leak of your data.