Effective Date: December 1, 2022
Website Covered: www.mailazy.com and all subdomains
As a security-focused company, we respect your information security. This policy describes how we use the data you provide and how we protect customer data.
Scope
This policy applies to all data collected, processed, or stored by Mailazy in the course of providing the service to our customers, including contact data, email content, and operational metadata.
Data Encryption
All data in transit between your application, our servers, and recipient mail servers is encrypted using TLS 1.2 or higher. All data at rest in our production databases and object stores is encrypted using AES-256. Encryption keys are managed via AWS KMS with annual rotation.
Access Controls
Access to production systems is restricted to authorized engineering personnel and protected by multi-factor authentication. We follow the principle of least privilege; access is revoked immediately upon role change or termination. All access is logged and audited.
Network Security
Production infrastructure runs in private VPCs with no direct internet exposure for application servers or databases. All inbound traffic is filtered through a web application firewall. DDoS protection is provided at the network edge.
Monitoring & Alerting
We continuously monitor our infrastructure for anomalous behavior including unauthorized access attempts, abnormal data exfiltration, and configuration drift. Security alerts are routed to our on-call team 24/7.
Vulnerability Management
We conduct regular vulnerability scans on our infrastructure and application code. Critical vulnerabilities are remediated within 7 days; high-severity within 30 days. We participate in coordinated disclosure with security researchers.
Backup & Disaster Recovery
Customer data is backed up daily with a retention period of 30 days. Backups are encrypted and stored in a geographically separate region. We test our disaster recovery procedures quarterly with a recovery time objective (RTO) of 4 hours.
Compliance & Audit
Mailazy maintains SOC 2 Type II certification (audited annually) and is GDPR-compliant for customers operating in the European Union. We sign Data Processing Agreements (DPAs) with customers on request.
Incident Response
In the event of a security incident affecting customer data, we will notify affected customers within 72 hours of confirmation. Our incident response plan is documented and tested annually. Post-incident reports are shared with affected customers.
Employee Security
All Mailazy employees and contractors undergo background checks where legally permitted. Annual security awareness training is mandatory. Employees sign confidentiality agreements and acceptable-use policies upon onboarding.
Subprocessors
We use a limited set of subprocessors to deliver our service (AWS, Stripe, etc.). A current list of subprocessors is available on request. We perform security due diligence before onboarding any new subprocessor.
Contact
Questions about our security practices? Contact security@mailazy.com. Security disclosures should also be sent to this address.