Trust center

Security at EmailAudit

The controls implemented in EmailAudit today, the boundaries of those controls, and the operational work that remains.

Last updated September 4, 2026

Application controls

  • Scrypt password hashing and HTTP-only, same-site session cookies.
  • Workspace-bound authorization with owner, admin, analyst, and viewer roles.
  • Hashed scoped API keys and encrypted webhook signing secrets.
  • HMAC-signed webhooks, private-network destination blocking, rate limits, bounded input, and XML entity rejection.
  • Versioned database migrations, auditable background jobs, retry limits, and dead-letter status.

Data minimization

EmailAudit primarily evaluates public configuration. Stored private data is limited to accounts, workspace settings, monitoring history, uploaded reports, and integration material required for requested features.

Security testing boundary

Do not attempt to access, change, or disrupt other people’s accounts, data, domains, or systems. EmailAudit does not currently operate a public vulnerability-reward program or represent this page as authorization to test the service.

Operational maturity

The application includes secure defaults and automated release checks, but those controls are not a certification. Managed backup validation, production key rotation, independent vulnerability review, incident-response operations, and external uptime monitoring remain required before EmailAudit makes formal compliance or availability claims.