Security

Email is a trust business. Here is how we protect your account, your tokens and the messages flowing through PostedApi.

Last updated: September 2026

Encryption in transit and at rest

Every connection to PostedApi uses TLS 1.2 or newer, and stored data is encrypted with AES-256. Passwords and tokens are additionally hashed or encrypted in our database.

Two-factor authentication

Add a second factor to every sign-in with TOTP-based two-factor authentication. We recommend it for everyone and require it for administrator roles.

IP allowlisting for API

Lock each server token to the IP ranges you choose. Requests from anywhere else are rejected before they ever reach your streams.

Regular penetration testing

Independent security researchers probe our platform at least once a year, and every finding is triaged within 24 hours of confirmation.

Responsible disclosure

Found a vulnerability in PostedApi? We would genuinely like to hear about it. Send a description and, if possible, the steps to reproduce it to [email protected].

Please do not test against the production service, other customers' data, or third-party infrastructure without our written permission. Access only accounts and data you own. Good-faith reports are always welcome; we will not take legal action against researchers who act in good faith.

We acknowledge every report within 48 hours, keep you informed while we investigate, and credit you publicly if you want us to.

Compliance roadmap

Security is a process, not a badge. Here is where we stand on the formal frameworks:

  • GDPR — covered: rights, retention, transfers and our DPA are described on the GDPR page;
  • DPA — available to all paying customers on request;
  • SOC 2-style controls — our internal control framework is reviewed annually; a formal attestation is in progress;
  • ISO 27001 — under evaluation, with a decision expected before the end of the year.