Legal

Security Policy

Last updated: August 1, 2026

Template notice. This document is a plain-language starting point and is not legal advice. Have a lawyer review before you rely on it in production.

This page describes the security practices mailzy.us operates today and how to reach us about a suspected issue. It is maintained by mailzy.us and is a description of our own controls - not an independent audit, certification, or attestation.

Credential handling

  • Mailbox credentials are stored encrypted and shown only inside your authenticated dashboard.
  • We never send passwords over email, chat, or WhatsApp.
  • Access to production credential stores is limited to staff who need it for provisioning and support.

Platform controls

  • TLS on all traffic to the site and dashboard.
  • Encryption at rest for stored credentials and delivered lead-list files.
  • Row-level security in the primary database so accounts can only read their own records.
  • Managed authentication with hashed credentials and session expiry.
  • Edge-level bot mitigation and rate limiting.

Shared responsibility

We secure the platform, the provisioning process, and the credentials we hold. You are responsible for your own account: strong unique passwords, keeping your dashboard access private, controlling who on your team can see mailbox credentials, and securing the sending tools you connect. Once credentials leave our dashboard, their handling is in your control.

Reporting a vulnerability

Email hello@mailzy.us with the subject line "Security". Please include steps to reproduce, affected URLs, and any proof-of-concept detail. We aim to acknowledge within two business days.

We ask that you:

  • Give us reasonable time to fix an issue before publishing it.
  • Avoid accessing, modifying, or downloading data that is not yours.
  • Avoid denial-of-service testing, spam, social engineering, and physical attacks.

We will not pursue legal action against researchers who follow these guidelines in good faith. We do not currently run a paid bug bounty.

Incident response

If we confirm a breach affecting your personal data, we notify affected customers without undue delay and, where legally required, the relevant supervisory authority within 72 hours of becoming aware. Processor-side obligations are set out in the Data Processing Addendum.

Scope note

Mailbox infrastructure itself is operated by Google Workspace under Google's security programme. Payment card data is handled entirely by our payment processors; card numbers never reach our servers.

Ready to stop wiring DNS at midnight?

Launch your first mailboxes or your first lead list today. Cancel anytime.