Security & Compliance
Security & compliance, built in.
Encryption in transit and at rest, strict access controls, and a Data Processing Addendum for customers who need one.
Data protection
- AES-256-GCM on stored OAuth tokens and gateway credentials
- TLS 1.2 or better in transit, on web and SMTP
- Argon2id password hashing
- Data processed in the United States
Access control
- Two-factor auth: authenticator app, email code, backup codes
- API keys scoped to named permissions, revocable
- Role-based access control (RBAC)
- Sessions pinned to IP and user agent
Operational security
- Fail2ban and per-IP rate limiting on auth and SMTP
- Full security audit completed October 2025
- Origin checked on every state-changing API call
Customer controls
- Export your subscribers and billing history as CSV
- Data deletion within 90 days
- Sub-processor list available on request
- DPA available on request
Trust documents
Customers and prospective customers can request our Data Processing Addendum.