Encrypted in transit and at rest
Every connection is TLS 1.2 or better. API keys and DKIM private material are held in Cloudflare secret storage and are never written to D1, KV, R2, or application logs. Passwords are hashed with a memory-hard function.
Multi-factor authentication
TOTP-based MFA is available on every account, with recovery codes generated at enrolment. Password-only sign-in is not the intended end state — we will require MFA for anyone holding a privileged platform role.
Role-based access control
Tenant roles scope what a user can do (owner, billing, developer, read-only). Platform operators are separated into super-admin, support-admin, and billing-admin capabilities, so the person who can reset a password cannot also issue a refund.
Immutable audit log
Privileged actions — plan changes, quota overrides, credit adjustments, impersonation, suspension — are written to an append-only audit log with the acting account, the target, and a before/after detail payload. It is not editable through the application.
Scoped, rotatable API keys
Keys can be scoped to a single sending domain and to specific capabilities, so a key leaked from one integration cannot send from every domain you own. Keys can be rotated with an overlap window and revoked instantly.
Rate limiting and quota isolation
Every public entry point is rate-limited per tenant by a Durable Object, with a per-minute burst limit and separate daily and monthly send quotas. One tenant's traffic cannot consume another's allowance or the platform's SES quota.
Abuse controls on account creation
Signup is protected by Cloudflare Turnstile. Sends are additionally gated on verified sending domains, which prevents an unverified account from using us as an open relay.
Never logging what we shouldn't
Logs record identifiers and metadata — message ids, tenant ids, status transitions, counts. Message bodies, recipient addresses, and API key secrets are not written to logs or analytics.