Back to Tools
Red Sift logo

Red Sift

Partially Compliant

UK email security and DMARC platform covering domain authentication, BIMI and certificate monitoring, with data transfers to the US under the Data Privacy Framework.

๐Ÿ‡ฌ๐Ÿ‡งUnited KingdomNon-EU ยท United Kingdom

Subject to the US CLOUD Act: a US parent company can be compelled to disclose data it holds, including data stored in the EU.

Paid
Red Sift website screenshot

GDPR Compliance Data

Not independently verified
GDPR Status
Partially Compliant
HQ CountryUnited Kingdom
OwnershipNon-European
Foreign Disclosure ExposureUS CLOUD Act / FISA 702
Data Hosting Location
Unknown
EU Servers Available
Data Processing AgreementNot verified
Sub-processor ListNot verified
Schrems II Risk
High Risk
SCCs in Place
Last Verified1 September 2026

How we reached this

UK legal entity: Redsift Limited, from the privacy policy read 2026-09-01. Exposure US_CLOUD_ACT and Schrems II risk HIGH on the vendor's own words: "We may transfer your Personal Data to countries or territories whose laws have not been deemed to provide such an adequate level of protection (e.g., the United States)." It relies on adequacy decisions and frameworks including the EU-U.S. Data Privacy Framework and the UK Extension where applicable, and states that "in limited circumstances, we may rely on an exception, or 'derogation', which permits us to transfer your Personal Data to such country despite the absence of an 'adequacy decision' or 'appropriate safeguards' - for example, reliance on your explicit consent to that transfer". Article 49 derogations are intended to be exceptional and occasional rather than a standing transfer mechanism, so a vendor naming one is describing the shape of its data flows and the risk is rated accordingly. PARTIAL: no hosting region is stated, and no sub-processor list or DPA was located at a public URL. The policy also carries the disclaimer "as our Site and Platform are hosted electronically, we can make no guarantees as to the security or privacy of your information", which is unusual wording for a security vendor. Ownership NON_EU: the UK is a third country under GDPR with a reviewable adequacy decision, and the Investigatory Powers Act reaches data held by UK providers.

About Red Sift

Email Authentication, From the Security Side

Red Sift approaches the same problem as DMARC Advisor from a different direction. Where DMARC Advisor is a focused reporting and management tool with a โ‚ฌ19 entry price, Red Sift is a broader domain security suite: DMARC and authentication, yes, but also BIMI, certificate lifecycle monitoring, and discovery of the domains and assets an organisation did not know it had.

That makes it a purchase a security team signs off on rather than a marketing tool, and it prices accordingly.

Why Marketers End Up Here Anyway

Email authentication is one of the few places where marketing and security genuinely share a control. Get DMARC wrong and campaigns stop arriving; get it right and both deliverability and spoofing protection improve at once. Since Google and Yahoo tightened bulk sender requirements, this stopped being optional for anyone sending at volume.

The Data Position, Stated Plainly

Published by Redsift Limited. The privacy policy is unambiguous about international transfers:

We may transfer your Personal Data to countries or territories whose laws have not been deemed to provide such an adequate level of protection (e.g., the United States).

It relies on adequacy decisions and frameworks including the EU-U.S. Data Privacy Framework and the UK Extension where they apply, and notes that in limited circumstances it may rely on a derogation such as explicit consent where neither an adequacy decision nor appropriate safeguards are available.

That last point deserves attention. Derogations under Article 49 are meant to be exceptional and occasional, not a standing transfer mechanism, and a vendor that flags it is telling you something about the shape of its data flows. Read together with the US transfers, this is a platform that does not keep your data in Europe, and does not claim to.

No hosting region is stated, and no sub-processor list or DPA was located at a public URL. The policy also carries an unusual disclaimer: "as our Site and Platform are hosted electronically, we can make no guarantees as to the security or privacy of your information."

The Fair Comparison

If you want DMARC management with the data staying in the EU, DMARC Advisor is the Dutch answer and it starts at โ‚ฌ19 a month. If you need certificate management, attack-surface discovery and a security-grade platform, Red Sift covers ground DMARC Advisor does not, and you accept US processing to get it. Both are legitimate choices; this directory's job is making sure you know which one you are making. See email deliverability.

Key Features

DMARC deployment, monitoring and reporting
SPF and DKIM management
BIMI configuration and logo verification
Certificate lifecycle monitoring
Attack surface and domain discovery
Alerting on authentication and certificate changes
Reporting for security and marketing stakeholders
Enterprise-grade access controls

Pros & Cons

Covers ground a pure DMARC tool does not: certificates, attack surface, domain discovery
Built to a security-team standard rather than a marketing-tool standard
Explicit and honest about transferring data outside adequate jurisdictions
Addresses the deliverability control that Google and Yahoo bulk sender rules made mandatory
Established platform with enterprise deployment experience
States that it transfers personal data to countries without adequacy, naming the United States
Discloses reliance on Article 49 derogations, which are meant to be exceptional rather than routine
No hosting region, sub-processor list or DPA published
Security-suite pricing rather than a marketing-tool price point
The policy disclaims guarantees about the security or privacy of your information

Red Sift GDPR & data protection: common questions

Is Red Sift GDPR compliant?

Partly. Red Sift meets some of the requirements, with caveats worth reading before you commit. Red Sift is based in United Kingdom, outside the EU/EEA.

Where does Red Sift store data?

We could not locate a clear statement of where Red Sift hosts data. Ask the vendor directly, or check their privacy policy and sub-processor list before signing.

Does Red Sift offer a Data Processing Agreement (DPA)?

We could not locate a published DPA for Red Sift. That does not mean one is unavailable. Many vendors provide it on request or inside the account area rather than publishing it. Ask before you sign.

What a DPA has to cover โ†’

Is Red Sift a European company?

No. Red Sift is based in United Kingdom, outside the EU/EEA. It may still be a sound choice (EU hosting and a signed DPA matter more than a flag) but the ownership is not European.

Is Red Sift subject to the US CLOUD Act?

Yes. US authorities can compel disclosure of data held by a US company or its subsidiaries, regardless of the country the servers sit in. EU hosting alone does not remove this, the question is who controls the data, not where the disk is.

Schrems II compliance checklist โ†’

Spotted something wrong?

Martech moves fast. Vendors change hosting regions, get acquired, publish a new DPA or rewrite their pricing, and they rarely announce it. We check what we publish and date every compliance review, but some of what you see here will be out of date before we catch it.

If you work at Red Sift and something on this page is wrong, tell us and we will fix it. Readers, same invitation. Pointing us at the page that proves it gets it changed fastest.