Enterprise Security

Protecting your data in transit and at rest

Designed from the ground up for strict confidentiality and compliance.

Encrypted in Transit

All inbound API traffic requires HTTPS with TLS 1.3. Outbound SMTP dispatches utilize opportunistic STARTTLS with modern ciphers.

Scoped API Keys & One-Time Reveals

Raw API secrets and SMTP passwords are never stored in plaintext and cannot be read after creation. SHA-256 hashes are used for verification.

Automated Abuse Protection

Dynamic IP rate limiting, per-user OTP threshold throttles, and automated hard-bounce suppressions safeguard our shared IP reputations.

Complete Account Isolation

Tenants have isolated databases of logs, suppression records, API keys, and custom sender domains protected by Laravel authorization policies.