Skip to content

Enterprise-Grade Security

Your DNS and email infrastructure security is our top priority

Security Measures

Comprehensive protection across every layer of our platform

Data Encryption

  • AES-256 encryption at rest
  • TLS 1.3 in transit
  • Encrypted credential storage (KMS-managed keys)

Access Control

  • Multi-factor authentication
  • Role-based permissions
  • API token scoping and rotation

Compliance

  • SOC 2 Type II (report available under NDA)
  • GDPR compliant processing
  • CCPA ready practices

Infrastructure

  • AWS infrastructure
  • 99.9% uptime SLA
  • Multi-region redundancy

Security Practices

Continuous improvement through rigorous processes and proactive monitoring

Penetration Testing

Scheduled at least annually with remediation follow-ups. Third-party security experts conduct comprehensive testing to identify and address vulnerabilities.

Vulnerability Disclosure

Public policy with standard triage and response procedures. Dedicated contact at security@inboxgreen.com for responsible disclosure.

Incident Response

Detect, contain, eradicate, recover, and postmortem process. Communications within defined SLAs to affected customers and stakeholders.

Data Retention

Minimal collection philosophy with scoped access controls. Retention windows documented and customer-requested deletion honored promptly.

Change Management

Peer review requirements, automated CI/CD gates, and comprehensive audit trails for all production changes.

Backups

Encrypted backups with periodic integrity checks and tested restore procedures to ensure data recovery capabilities.

Security Lifecycle

Our security practices follow a continuous improvement cycle to stay ahead of emerging threats.

1

Assess

Regular audits and testing

2

Protect

Implement controls and safeguards

3

Detect

Monitor for threats 24/7

4

Respond

Rapid incident management

5

Improve

Learn and adapt processes

Have a security concern or question?

security@inboxgreen.com

Trust Center

Transparency and accountability through comprehensive documentation

Downloadable Reports

Access our security compliance documentation

  • SOC 2 Type II Report (under NDA)
  • Penetration Test Summary
  • DPA (Data Processing Agreement)

Audit Logs Access

Customer-visible event logs for transparency

Track all actions taken within your account including configuration changes, API calls, and user activities.

  • Available on Professional and Enterprise plans
  • 90-day retention (Enterprise: 1 year)
  • Exportable in CSV and JSON formats
Learn More About Plans

Security Whitepaper

Technical deep dive on our architecture

Comprehensive documentation covering our infrastructure design, data isolation strategies, encryption implementation, and security controls.

Download Whitepaper(PDF, 2.8 MB)

Subprocessors

Third-party service providers we use

Infrastructure:AWS (US-East, US-West, EU-West)
Monitoring:Datadog, Sentry
Email:SendGrid (transactional)
Last updated: January 15, 2025

Real-Time System Status

Monitor our platform uptime, performance metrics, and incident history in real-time.

View Status Page

This security page was last updated on