NewAI assistant and marketing suite, included on every plan

Legal

Security

Last updated: July 15, 2026

Encryption

  • All traffic between you and MailStrap, and between our servers, uses TLS (1.2+). Mail delivery uses TLS wherever the receiving server supports it.
  • Passwords are hashed with bcrypt and never stored or logged in plain text.
  • Sensitive stored secrets, DKIM private keys, API tokens, mail credentials, and two-factor secrets, are encrypted with AES-256 at the application layer before they reach the database.

Account protection

  • Passkeys (WebAuthn): phishing-resistant sign-in with Face ID, Windows Hello, or hardware keys.
  • Two-factor authentication: TOTP authenticator apps with one-time recovery codes.
  • New-location alerts: we email you when your account signs in from an IP address it hasn't used recently.
  • Session control: view and revoke active sessions from Settings.
  • Audit logging: sign-ins, password changes, 2FA and passkey changes are recorded and visible to you in Settings.

Platform isolation

  • Every organization is a separate tenant: mailboxes, files, and documents are scoped to your organization and, within it, to explicit per-user access grants.
  • We run our own mail infrastructure (no third party reads your mailboxes) and our own video-meeting servers.
  • Outbound mail passes automated abuse screening so one bad actor can't burn the deliverability every customer relies on.
  • Webhooks from our providers are cryptographically signature-verified before we act on them.

Infrastructure

  • Hosted on Amazon Web Services (us-east-1) with managed databases and encrypted backups.
  • File storage on Amazon S3, accessed only through short-lived signed URLs.
  • Payment card data is handled entirely by Stripe (PCI DSS Level 1); it never touches our servers.

Reliability and uptime

  • We stand behind a 100% uptime SLA on the core service: if it is unavailable during a billing period, affected customers can claim service credits for that time.
  • Uptime is published live at status.mailstrap.com and monitored from both inside and outside our cloud, so an outage can't hide itself.
  • Nightly encrypted backups of mail and databases are taken and retained, with recovery tested.

Data protection and GDPR

MailStrap acts as your data processor. A Data Processing Agreement is available at /dpa and the full list of subprocessors at /subprocessors. You can export your data or permanently delete your account and its contents at any time from Settings.

What we don't claim

We are a young company and honesty beats badges: we do not yet hold SOC 2 or ISO 27001 certifications. As the platform grows we intend to pursue them. If your organization needs specific security documentation, write to us and we'll share details of our current practices.

Responsible disclosure

Found a vulnerability? Email hello@mailstrap.com with the subject “SECURITY”. We respond within 48 hours, won't take legal action against good-faith research, and credit reporters who want it. Please don't access other people's data or degrade the service while testing.