Security at Mailfully
The API and dashboard answer over HTTPS only, and the data we store is encrypted at rest.
Your data
- Plain HTTP requests to the API and the dashboard are redirected to HTTPS.
- Encryption at rest covers the database, the cache and stored received mail.
- Mailfully runs in the United States.
- The full list of subprocessors is in the privacy policy.
Your account
- Passwords are stored as scrypt hashes.
- An API key is shown once, and only a hash of it is stored.
- A key can be read-only, so it cannot send. It can also be tied to one sending domain. No key can create or revoke other keys.
If a key leaks, revoke it. A revoked key stops working on its next request. Rotating a key leaves the old one working for 24 hours while you deploy the new one, so use rotation for planned changes.
Your mail
What we do not have yet
We don't have a SOC 2 or ISO 27001 report yet, and we don't sign HIPAA business associate agreements (BAAs).
Reporting a problem
If you find a security problem in Mailfully, write to contact@mailfully.com.