Do you encrypt data at rest?
Yes. Message objects are encrypted with a deployment-managed key before filesystem/object storage. This is encryption at rest, not end-to-end encryption — the service must decrypt to parse and render mail.
Trust Center
Enterprise-friendly detail on how Mailby protects disposable and private inboxes — without unsupported certification badges.
No public SMTP AUTH, no open relay, no VRFY/EXPN.
Address knowledge never grants read access.
HttpOnly host cookies, CSRF on mutations, hashed secrets at rest.
Postfix queue + private LMTP; ACK only after durable store.
Allowlist HTML sanitization, sandboxed preview, blocked remote content by default.
Immediate revoke + tracked purge of objects, extracts, and grants.
HTTPS for app; opportunistic STARTTLS for inbound SMTP.
Rate limits, reserved names, anti-reuse tombstones, recipient policy at RCPT.
Use these answers in vendor reviews. Keep claims aligned with implemented controls.
Yes. Message objects are encrypted with a deployment-managed key before filesystem/object storage. This is encryption at rest, not end-to-end encryption — the service must decrypt to parse and render mail.
Application traffic is HTTPS. Inbound SMTP supports STARTTLS. Authenticated capture (developer plane) requires TLS before credentials.
Authorized inbox holders and scoped workers that parse/scan. Platform support defaults to metadata-only; content requires an expiring audited grant.
Quick Free: 1 hour receiving lease and 1 hour message retention unless deleted earlier. Paid plans expose longer selectable windows from the entitlement catalog.
No. Message content is never used for advertising, model training, profiling, or sale.
Not claimed on this page. Controls above reflect implemented engineering posture. Certification status is published separately when an independent report is available.
Pilot host processes mail on operator-controlled infrastructure (PostgreSQL, Redis, object storage, Postfix). Transactional billing/email providers are listed when enabled.
Security incidents follow detection → containment → customer notification when content exposure is confirmed → postmortem. Contact security@mailby.app for reports.