Trust Center

Security & data handling

Enterprise-friendly detail on how Mailby protects disposable and private inboxes — without unsupported certification badges.

Receive-only public plane

No public SMTP AUTH, no open relay, no VRFY/EXPN.

Per-inbox authorization

Address knowledge never grants read access.

Opaque sessions

HttpOnly host cookies, CSRF on mutations, hashed secrets at rest.

Durable ingress

Postfix queue + private LMTP; ACK only after durable store.

Safe rendering

Allowlist HTML sanitization, sandboxed preview, blocked remote content by default.

Deletion workflow

Immediate revoke + tracked purge of objects, extracts, and grants.

Transport security

HTTPS for app; opportunistic STARTTLS for inbound SMTP.

Abuse controls

Rate limits, reserved names, anti-reuse tombstones, recipient policy at RCPT.

Compliance & privacy summary

  • Data minimization: keep message bodies only for the entitled retention window.
  • Backups are a separate retention class (default 7 days) with deletion-ledger replay on restore.
  • Address anti-reuse tombstones store a keyed HMAC, not message content.
  • Legal/privacy applicability depends on operator entity and markets; this page describes product behavior.

Security questionnaire (SOC 2 style)

Use these answers in vendor reviews. Keep claims aligned with implemented controls.

Do you encrypt data at rest?

Yes. Message objects are encrypted with a deployment-managed key before filesystem/object storage. This is encryption at rest, not end-to-end encryption — the service must decrypt to parse and render mail.

Do you encrypt data in transit?

Application traffic is HTTPS. Inbound SMTP supports STARTTLS. Authenticated capture (developer plane) requires TLS before credentials.

Who can access customer email content?

Authorized inbox holders and scoped workers that parse/scan. Platform support defaults to metadata-only; content requires an expiring audited grant.

What is your retention default?

Quick Free: 1 hour receiving lease and 1 hour message retention unless deleted earlier. Paid plans expose longer selectable windows from the entitlement catalog.

Do you sell or train on message content?

No. Message content is never used for advertising, model training, profiling, or sale.

Are you SOC 2 certified?

Not claimed on this page. Controls above reflect implemented engineering posture. Certification status is published separately when an independent report is available.

Subprocessors?

Pilot host processes mail on operator-controlled infrastructure (PostgreSQL, Redis, object storage, Postfix). Transactional billing/email providers are listed when enabled.

Incident response?

Security incidents follow detection → containment → customer notification when content exposure is confirmed → postmortem. Contact security@mailby.app for reports.

Post-certification update checklist

  1. Publish report date, scope, and exceptions — never a badge alone.
  2. Update this page, subprocessors, DPA offer, and sales one-pager together.
  3. Diff questionnaire answers against the auditor report; remove aspirational language.
  4. Schedule control evidence refresh (access reviews, backup restore drill, purge SLOs).
  5. Brief support/sales on wording: implemented vs certified vs roadmap.

Enterprise sales wording

  • Say: “Receive-only disposable mail with per-inbox auth and timed deletion.”
  • Avoid: “fully anonymous,” “zero logs,” “undetectable,” “GDPR certified.”
  • Say: “Encryption at rest and TLS in transit; not E2EE.”
  • Say: “We report observed delivery stages, not sender-side guarantees.”
Support: security@mailby.app · Abuse: /abuse