Trust

Security

How the system is built, what we can see, and what we do not have yet. Written for the person doing your security review.

Last updated 18 September 2026

Outbound and inbound use separate transports

Outbound messages are submitted to SMTP2GO. Sender domains must be verified, and requests are checked against API-key scopes, organization and brand restrictions, suppressions, and usage limits. Sending infrastructure is shared; a brand is not a dedicated provider account or IP address.

The existing inbound transport uses Amazon SES receiving, SQS event processing and S3 raw-message storage. Outbound delivery changes do not change receiving MX records or the existing message archive.

We retain message metadata, delivery events and stored message bodies for inbox and sent views. Incoming raw messages can include attachments. The API sanitizes HTML when it is served and blocks downloads flagged as infected.

Tenant isolation

Production PostgreSQL row-level security scopes data access to an organization. The application also enforces ownership and API-key brand restrictions. Production uses a database role that is not the table owner; embedded development databases do not provide that same RLS boundary.

API keys are stored as SHA-256 digests with a display prefix and last four characters. The plaintext is shown once, and keys can be scoped, expired or revoked.

Provider credentials

SMTP2GO credentials are configured on the server and never returned to API clients. DNS provider credentials are also server-side. General DNS changes require an independently published ownership TXT record and are restricted to the authorized domain.

SMTP2GO delivery events use the configured webhook authentication. Incoming receiving events and raw archive access continue to use the receiving infrastructure's credentials.

Services that process data

  • SMTP2GO — outbound message delivery and delivery events
  • Amazon Web Services — the existing inbound receiving transport, event queue and raw message archive
  • Application and database hosting — the deployment operator's configured host
  • Cloudflare — DNS publication when configured for the domain

The deployment and provider accounts determine processing locations. Ask for the deployment-specific processor and region information before relying on a residency requirement.

What an incident could expose

A database breach could expose organization data, addresses, subjects, stored message bodies, delivery history and suppression lists. A raw archive breach could also expose incoming attachments. API-key hashes do not reveal the original token, but a compromised application process can access its configured provider credentials.

We do not claim dedicated provider reputation isolation, a SOC 2 report, or an independent penetration-test certification. Contact us with your review requirements.

Questions a page cannot answer go to security@mycompany.email. There is no sales team in front of it.