Security & Compliance

Security & compliance, built in.

Encryption in transit and at rest, strict access controls, and a Data Processing Addendum for customers who need one.

GDPR
DPA available

Data protection

  • AES-256-GCM on stored OAuth tokens and gateway credentials
  • TLS 1.2 or better in transit, on web and SMTP
  • Argon2id password hashing
  • Data processed in the United States

Access control

  • Two-factor auth: authenticator app, email code, backup codes
  • API keys scoped to named permissions, revocable
  • Role-based access control (RBAC)
  • Sessions pinned to IP and user agent

Operational security

  • Fail2ban and per-IP rate limiting on auth and SMTP
  • Full security audit completed October 2025
  • Origin checked on every state-changing API call

Customer controls

  • Export your subscribers and billing history as CSV
  • Data deletion within 90 days
  • Sub-processor list available on request
  • DPA available on request

Trust documents

Customers and prospective customers can request our Data Processing Addendum.

View DPA Request docs