Security
Trust & Security
Mailsurity is built on certified infrastructure with privacy by design. This page summarizes our security practices, the certifications of the providers we rely on, and how we handle your data.
Last updated: June 24, 2026
Our approach
We follow a data-minimization-first design: we process the minimum data needed to detect disposable email addresses, retain it for the shortest practical time, and lean on certified infrastructure providers rather than rolling our own. We are not formally SOC 2 / ISO 27001 certified as a company; instead we build on providers who are, and we are transparent about exactly what we do.
Infrastructure & sub-processor certifications
Your data is processed only by a small set of vetted providers, each of which maintains independent security attestations. Certifications below reflect each provider's current published reports — see their trust pages for the latest.
Supabase
Database, authentication & file storage
Hosted in AWS ap-south-1 (Mumbai).
Vercel
Application & API hosting
Stripe
Subscription billing
We never see or store full card numbers.
Google Cloud (Gemini)
AI classification of gray-zone domains
Only the email domain is sent — never the local-part.
Upstash
Redis cache
Domain-level cache only — never full email addresses.
Resend
Transactional email
Account & billing notifications only.
Data protection
- Encryption — all data is encrypted in transit (TLS) and at rest (AES-256) by our infrastructure providers.
- Access control — production data access is scoped and limited; customer API access uses per-team bearer tokens you can revoke at any time from your dashboard.
- Tenant isolation — every query is scoped to your team; one customer can never read another's data.
- Secrets — API keys are shown in full only once at creation and stored for verification; we display only the last four characters thereafter.
Data handling & retention
- API request logs — the checked email and originating IP are automatically anonymized 90 days after the request. Only aggregate, non-identifying metrics (timestamp, account, verdict) are kept beyond that, for billing and analytics.
- Bulk-check files — uploaded CSVs are deleted after 7 days; generated result files after 30 days.
- AI classification — only the email domain is ever sent to our AI provider; the local-part (the text before the
@) never leaves our systems. - Caches — operational caches store domain-level detection results only, for short, fixed periods.
Your privacy rights
We support the core GDPR data-subject rights directly from your account:
- Access & portability — download a machine-readable export of your account and team data from Security settings.
- Erasure — delete your account and associated data from the same page; personal data is anonymized or removed.
- Rectification — update your profile and organization details in Team settings.
GDPR & international transfers
We act as a data processor for the customer data you submit. Our Data Processing Agreement sets out our commitments, the full sub-processor list, and the Standard Contractual Clauses that govern transfers of EEA/UK/Swiss data. A Record of Processing Activities (Art. 30) is available to customers on request. See our Privacy Policy for the full detail.
Incident response
In the event of a personal-data breach affecting your data, we will notify affected customers without undue delay and, where required, within 72 hours of becoming aware — including the nature of the incident, likely consequences, and the measures taken.
Reporting a vulnerability
If you believe you've found a security vulnerability, please email us at support@mailsurity.com. We appreciate responsible disclosure and will work with you to confirm and address valid reports promptly. Please do not publicly disclose an issue before we've had a chance to remediate it.