Security and compliance
Protecting your campaign data, domain reputation, and customer privacy is fundamental to everything we engineer.
Architectural safeguards
Encryption in transit and at rest
All web traffic, API requests, and webhook payloads are strictly encrypted with TLS 1.3. Stored campaign data, recipient lists, and system state are encrypted at rest using industry-standard AES-256 encryption.
Isolated cloud infrastructure
Our services run on modern enterprise cloud infrastructure with zero-trust networking, multi-region database redundancy, automated daily backups, and real-time perimeter monitoring against DDoS threats.
Outbound deliverability safeguards
Automated SPF, DKIM, and DMARC health validation, ramp-up schedules, intelligent warmup throttling, and automated bounce detection ensure domain protection and safe outbound sending.
Access control and workspace isolation
Multi-tenant architecture provides strict data isolation between customer workspaces. Role-based access controls (RBAC) and secure token authentication prevent unauthorized data leakage.
Operational safeguards
Engineered for reliability, privacy, and continuous protection
Mailboxes authenticate via secure OAuth2 tokens whenever supported. Raw passwords are never accessible in plain text.
Continuous audit logging, anomaly detection, rate-limiting, and automated intrusion prevention systems.
Built-in data export and permanent deletion pipelines to honor end-user privacy and data subject requests promptly.
You retain full ownership of your contacts, email templates, and campaign history. We never sell or share your audience data.
Vulnerability reporting
We value reports from the security research community. If you believe you have found a security vulnerability or have compliance inquiries, please notify our team directly.
Contact the security team