Security is a feature, not a tab.
We built Mailapp to handle the data you wouldn't hand to anyone else. This page is our standing answer to your security review.
The compliance you'd expect, the evidence you can audit.
EU-aligned data handling. DPA available without negotiation for any customer.
California consumer rights honoured globally by default.
Mailapp never stores cardholder data. Payments processed by Stripe (PCI Level 1).
Your data, where you need it.
EU customers stay in the EU. Nothing crosses a border without your explicit consent.
How we operate, in plain English.
TLS 1.3 in transit, AES-256 at rest. All keys rotated quarterly via AWS KMS. Customer-managed keys available on Enterprise.
Engineers don't access customer data by default. Every read is logged with a justification and routed to your dedicated audit log if you enable it.
Anomaly detection on every privileged action. Alerts route to a 24/7 on-call rotation. Median mean-time-to-detect is under 6 minutes.
AI prompts never train shared models. Local model endpoints available for regulated industries. PII redaction is on by default.
Logical isolation by default, physical isolation available on Enterprise. Test data is segregated and purged on a 30-day cycle.
Practiced quarterly via tabletop and game days. We publish post-mortems for any incident of severity 2 or higher.
Every party with a chance to touch your data.
We notify on changes at least 30 days in advance. Customers can opt out of any change before it takes effect.
A bounty program, not a PR program.
Reported in good faith, paid promptly. Our scopes and bounty bands below. Submit via hello@mailapp.app or HackerOne.
Every contract and policy, in one place.
Every paid plan automatically gets our DPA. Every page is plain-English first, then the legalese. No mystery PDFs, no NDAs to read the policies.
What we collect, why, and how to delete it. GDPR + CCPA aligned.
Read privacyThe agreement between you and Mailapp. With plain-English summaries.
Read termsEvery cookie, who sets it, why, how to refuse it.
Read cookiesEU SCCs, UK IDTA, sub-processor notice. No negotiation needed.
Read DPAWhat we don't allow. Read this before your first send.
Read AUPCAN-SPAM, CASL, GDPR, ePrivacy, Yahoo/Google 2024 — and our own bar.
Read anti-spamWhen we refund, when we don't, and how SLA credits work.
Read refund policyAccess, correct, export, delete, restrict, object. Global by default.
Submit a requestEvery vendor that could touch your data, with 30-day change notice.
See sub-processors