Boring security,
on purpose.
The practices below are in the product today. Where an audit is still in progress, this page says so.
Account security
Two factor authentication is available and recommended on every account. Sessions and API keys can be revoked at any time.
Scoped API access
API keys carry scopes, rate limits and expiry, and can be restricted to specific IP addresses. Every key has its own request log, and webhooks carry a delivery log you can replay from.
Suppression enforced at send time
Unsubscribes, bounces and complaints are held against the contact with the reason and source recorded, and every send respects them on every channel. This is enforced by the platform, not by policy.
Your data stays yours
Contacts, templates and reports belong to you. Contacts export at any time, and migration never writes anything until you have previewed what moves. We do not sell personal data.
Certifications
Formal audits are in progress. We will publish reports here when they complete rather than claiming them early.