Security

    Enterprise-Grade Security

    Your data security is our top priority. Learn about our comprehensive security measures.

    User-Level Email Encryption

    Validated emails are encrypted using AES-256-GCM with per-user derived keys. Each user's data is encrypted with a unique key derived from their user ID, ensuring complete data isolation.

    Active

    Data at Rest Encryption

    All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption. Your API keys are stored with one-way hashing.

    Infrastructure Security

    Our infrastructure is hosted on SOC 2 Type II certified cloud providers with automatic security updates and intrusion detection.

    Access Controls

    Role-based access control (RBAC), multi-factor authentication, and IP whitelisting options for enterprise accounts.

    Compliance

    GDPR, CCPA, and SOC 2 compliant. Regular third-party security audits and penetration testing.

    Monitoring

    24/7 system monitoring, automated threat detection, and incident response procedures to ensure service integrity.

    Data Protection

    Validated email addresses are automatically deleted after 90 days. No sharing of data with third parties.

    Security Best Practices

    For All Users:

    • Use strong, unique passwords
    • Enable two-factor authentication
    • Keep API keys secure and never expose them in client-side code
    • Regularly rotate API keys

    For Enterprise Customers:

    • Implement IP whitelisting for API access
    • Use dedicated API keys for different applications
    • Monitor API usage and set up alerts for unusual activity
    • Conduct regular security reviews of your integration

    Report a Security Issue

    If you discover a security vulnerability, please report it to us immediately. We take all security reports seriously and will respond promptly.

    Email: support@verimailx.com

    Please include detailed information about the vulnerability and steps to reproduce it.