Security & Trust
Security Overview
This Security Overview describes Emailble’s security posture, safeguards, customer responsibilities, incident handling principles and beta-stage limitations.
1. Security Approach
Emailble is designed with reasonable administrative, technical and organisational safeguards appropriate to a cloud service that handles account data, contact data, campaign data, tracking data, verification data, AI usage records, billing records and connected sending routes.
Security is an ongoing process. Emailble does not claim perfect security, guaranteed protection, SOC 2 certification, ISO certification, enterprise-grade certification or production SLA-backed security unless and until such controls are actually implemented, audited and approved for public statement.
2. Safeguards
- HTTPS/TLS for web access where configured.
- Account and workspace access controls.
- Tenant-separation design principles.
- Credential-protection and secret-handling practices.
- Audit logging and operational records where implemented.
- Abuse monitoring, suppression controls and campaign review signals.
- Provider security controls for infrastructure, payments, AI, verification and sending routes.
- Incident review and response procedures appropriate to the maturity of the service.
3. Customer Responsibilities
The customer must protect passwords, devices, sessions, sender accounts, API keys, DNS records, provider credentials, payment access and administrator permissions. The customer should remove users who no longer need access and promptly report suspected compromise.
Emailble is not responsible for unauthorised access caused by the customer’s failure to secure its users, devices, credentials, connected providers, email accounts or third-party systems except to the extent required by applicable law.
4. Connected Providers and Keys
Where the customer connects a sending provider, SMTP route, API key, AI key or other third-party account, the customer is responsible for using authorised credentials, configuring provider security, following provider rules and monitoring provider account activity.
Emailble may restrict, disable or require re-authentication of connected routes or keys where compromise, misuse, provider warnings, suspicious activity or configuration risk is detected.
5. Security Logs and Evidence
Emailble may retain security logs, access records, event records, provider responses, confirmation records and diagnostic data to protect the service, investigate incidents, respond to complaints, support enforcement, handle disputes and comply with law.
Logs may include technical information such as user identifiers, workspace identifiers, IP-related information where lawful, user agent, timestamps, route identifiers, event types, errors and security signals.
6. Incidents and Breach Handling
Emailble will assess suspected security incidents according to the nature of the event, the data involved, the customer role, the legal requirements, the provider context and the risk to affected persons. Where notification is legally required, Emailble will make notifications according to applicable law and the relevant data role.
Customers must notify Emailble promptly if they suspect unauthorised account access, exposed credentials, compromised provider routes, unauthorised exports, suspicious campaigns, phishing, malware or recipient-data compromise.
7. Limitations
No security program can prevent every risk. Emailble does not warrant that the service will be immune from attack, uninterrupted, error-free, free of vulnerabilities or compatible with every customer security requirement. Customers with regulated or enterprise needs should request additional contractual terms before using Emailble for high-risk data.
Security Reports
To reduce public email harvesting, the address is hidden until requested.