Skip to content

Security at Mailfully

The API and dashboard answer over HTTPS only, and the data we store is encrypted at rest.

Your data

  • Plain HTTP requests to the API and the dashboard are redirected to HTTPS.
  • Encryption at rest covers the database, the cache and stored received mail.
  • Mailfully runs in the United States.
  • The full list of subprocessors is in the privacy policy.

Your account

  • Passwords are stored as scrypt hashes.
  • An API key is shown once, and only a hash of it is stored.
  • A key can be read-only, so it cannot send. It can also be tied to one sending domain. No key can create or revoke other keys.

If a key leaks, revoke it. A revoked key stops working on its next request. Rotating a key leaves the old one working for 24 hours while you deploy the new one, so use rotation for planned changes.

Your mail

  • Webhooks are signed, so you can check that a request came from us.
  • Test mode never delivers to a real inbox.

What we do not have yet

We don't have a SOC 2 or ISO 27001 report yet, and we don't sign HIPAA business associate agreements (BAAs).

Reporting a problem

If you find a security problem in Mailfully, write to contact@mailfully.com.