Concepts
How customer data is handled
What HRS Triage stores, who can read message content, and exactly what leaves the platform.
Who can read reported email
Only analysts and admins. Viewers see that a case exists, its verdict, score, reasons and indicators, but never the message body, headers or attachments. Everyone sees only the organizations in their scope.
What leaves the platform, and only when
| Goes to | What | When |
|---|---|---|
| Your mail platform | Quarantine, restore, reporter emails | After approval, or when your auto-remediation threshold allows |
| Reputation services | Lookups of links, domains and attachment hashes (never the files): URLhaus, ThreatFox, urlscan.io, Google Safe Browsing, VirusTotal | Automatically, for the services HRS has turned on |
| Nobody | Checks against the downloaded threat feeds (OpenPhish, PhishTank, URLhaus, ThreatFox, Phishing Army, CERT Polska and, if switched on, Phishing.Database) | Those lists are downloaded and compared inside HRS Triage; your links are never sent to them |
| AI provider (Anthropic) | The message, for assessment, and the context of an Ask HRS AI question | Only if an admin turns AI on. With your own AI key, it goes to your own Anthropic account under your agreement with them; otherwise to HRS's account |
| urlscan.io / VirusTotal Private | One link or attachment, privately | Only when an analyst presses Detonate, after an admin allows it |
| Your chat, ticketing, SIEM, webhooks | Case summaries and indicators | Only destinations your admin connects |
| Other HRS customers | An indicator and a count, never content or your identity | Only if an admin turns on contribution |
Protected by default
- Rendered email has links disabled and remote content blocked.
- Credentials for connected tools are encrypted and never displayed again.
- Every change is audited.
- Sessions end after inactivity; see Sessions and idle sign-out.
Still stuck?Contact support