Security

Built approval-first, audited end to end

Every item below is a control that exists in the product today. Ask us for the details of any of them.

Approval-first by design

Anything that spends money, writes DNS, buys domains or sends to the outside world is staged as an approval a human grants. Six consequential actions additionally require a second factor at decision time.

Two-factor authentication

TOTP with any authenticator app, ten single-use recovery codes, and a platform setting that requires two-factor on every staff account. Sessions are invalidated on password reset.

Credentials encrypted at rest

OAuth tokens, SMTP/IMAP passwords, provider API keys and integration keys are encrypted with a server-side master key that never leaves the host; secrets are never shown again after entry.

Least privilege

Ten workspace roles, from owner to viewer, gate every route server-side; staff tools are separate and capability-scoped; API keys are per-workspace and revocable.

Complete audit trail

Every change — sign-ins, approvals, sends, DNS writes, purchases, plan changes, staff actions — is written to an append-only audit log the workspace can read and export.

Your data, exportable and erasable

Self-service export of your workspace data, account deletion with a 30-day retention window, suppression lists honoured across every campaign, and per-workspace retention policies for message bodies.

Mail authentication and reputation

SPF, DKIM and DMARC are written and verified per domain; warmup, bounce breakers and blocklist checks pause sending before a provider does; placement is measured with your own seed mailboxes, never simulated.

Operational hygiene

Nightly verified database backups on a 14-day rotation (root-only, copied offsite when a bucket is configured), a public status page with live component checks, rate limiting on every public endpoint, signed webhooks, and a support desk that threads by ticket number.

Questions about compliance, data processing or a security review? Contact us — see also the Data Processing Agreement, Privacy Policy and Acceptable Use Policy, and the live status page.