gomailvibe
legal

Security at GoMailVibe

Last updated: 30 June 2026

1. Overview

Email is a system of record for many of our customers. We treat the data you bring to GoMailVibe with the same care we expect of our own banking provider. This page describes the security practices behind the Service.

2. Encryption

In transit: all connections to our APIs and dashboard use TLS 1.2 or higher. Outbound mail uses opportunistic TLS to receiving mailbox providers and enforced TLS where supported.

At rest: stored campaign content, recipient lists, and event data are encrypted with AES-256 on disk. Backups are encrypted with separate keys.

3. Access control

Internal access to production data is restricted to a small number of named engineers, gated by single sign-on with mandatory two-factor authentication. Every access is logged.

Customer-side access uses role-based permissions: owner, admin, and member. API keys are scoped to a workspace and can be revoked instantly.

4. Audit logging

Every significant action (login, key rotation, list import, campaign send) is recorded with a timestamp, the actor, and the IP address. Customers can request an audit log export for compliance reviews.

5. Authentication for senders

We require SPF, DKIM, and DMARC alignment on every sending domain before going live. Mail that does not pass authentication is held in queue and surfaced as a configuration warning.

6. Incident response

We maintain a documented incident response process: triage, containment, eradication, recovery, and post-mortem. For incidents affecting customer data, we will notify affected customers within 72 hours of discovery and publish a post-mortem within 14 days.

7. Vulnerability disclosure

We welcome security researchers. Report vulnerabilities to security@gomailvibe.com. We will acknowledge within two business days and keep you updated on remediation. We do not currently run a paid bounty programme but will credit researchers in our advisory.

8. Compliance posture

We are honest about where we are. As of this writing:

  • SOC 2 Type I: in progress, audit window underway
  • ISO 27001: planned for next year, not yet certified
  • GDPR: we operate as a data processor, DPA available on request
  • HIPAA: not supported. Do not send PHI through our system

We will update this section as our certifications progress. We will not list a certification we do not actually hold.

9. Sub-processors

We use a small number of infrastructure and tooling sub-processors (cloud hosting, payment processing, mailbox provider transit). A current list is available on request from security@gomailvibe.com.

10. Contact

Security questions, DPA requests, vulnerability reports: security@gomailvibe.com.