Security & Trust
Security & Trust at Mailmundo
Mailmundo is a US-based email-marketing platform operated by a US limited liability company, hosted on US soil, with billing in US dollars. We are built for service businesses that depend on reaching real inboxes, and we treat the protection of your account, your sender reputation, and your contacts as core product features—not afterthoughts. This page describes, in concrete terms, how we secure infrastructure and applications, how we enforce US email and privacy law, who our sub-processors are, and how we respond when something goes wrong. We document our posture honestly: where a control is live, we say so; where a certification is still in progress, we say that too.
Infrastructure & Encryption
Mailmundo runs on hardened, US-region cloud infrastructure with encryption applied to data both in transit and at rest, and with strict tenant isolation enforced at the database layer.
- Email delivery runs on Amazon Web Services (AWS) Simple Email Service (SES) in US regions; all mail is transmitted over opportunistic and enforced TLS where the receiving server supports it.
- All connections to our application and API are served over HTTPS using TLS 1.2 or higher; we do not accept unencrypted HTTP traffic for authenticated sessions.
- Data at rest—including your contact lists, campaigns, and metadata—is stored in PostgreSQL (Supabase) with AES-256 encryption at rest applied at the storage layer.
- Multi-tenant isolation is enforced in the database itself using PostgreSQL Row-Level Security (RLS) policies, so a given organization's queries can only ever return that organization's rows, independent of application-layer logic.
- Infrastructure is hosted within established US cloud regions, keeping primary processing and storage of your operational data on US soil.
Application Security
Access to Mailmundo is governed by strong authentication, scoped credentials, and least-privilege design, with an integrity-protected audit trail over sensitive actions.
- API keys are never stored in plaintext: we persist only a cryptographic hash of each key, so even in the event of a database disclosure your keys cannot be recovered and replayed.
- API keys are scoped: credentials are issued with the narrowest set of permissions needed for their purpose, following the principle of least privilege.
- Time-based one-time password (TOTP) multi-factor authentication (MFA) is supported, allowing you to require a second factor on top of your password for account access.
- Sensitive and administrative actions are recorded in a hash-chained audit log, where each entry is cryptographically linked to the previous one so that tampering or deletion of historical records is detectable.
- Internal access to production systems follows least-privilege principles, with access limited to the minimum personnel and scope required to operate the service.
Email Compliance & Deliverability
Mailmundo is engineered to keep your sending compliant with the US CAN-SPAM Act (15 U.S.C. 7701 et seq.; FTC rule at 16 CFR Part 316) and aligned with the 2024 Gmail and Yahoo bulk-sender requirements that now govern inbox placement.
- CAN-SPAM enforcement is built in: every commercial message must carry a functioning unsubscribe mechanism and the sender's valid physical postal address (16 CFR 316.2(p)—a street address, USPS-registered PO Box, or CMRA private mailbox), and we prohibit false or misleading headers and deceptive subject lines.
- Opt-out requests are honored automatically and promptly—well within the CAN-SPAM 10-business-day window—via global suppression lists that block future sends to any unsubscribed, bounced, or complained address across your account.
- We implement RFC 8058 one-click unsubscribe through the List-Unsubscribe and List-Unsubscribe-Post headers, satisfying the Gmail/Yahoo requirement (effective February 2024) that bulk senders offer one-click opt-out.
- We support and encourage SPF, DKIM, and DMARC authentication on your sending domains—the email-authentication trifecta Gmail and Yahoo require of senders at or above 5,000 messages per day.
- We help you stay under the platform spam-complaint thresholds—Google's 0.1% target and 0.3% hard ceiling—through suppression handling, bounce processing, and engagement-aware sending guidance.
Privacy & Data Rights
We process personal data under US state privacy law and, for international contacts, in a manner consistent with the GDPR and Brazil's LGPD, and we give you the tooling to honor data-subject requests.
- We support compliance with the California Consumer Privacy Act as amended by the CPRA (Cal. Civ. Code 1798.100 et seq.), including the rights to know, access, delete, correct, and opt out of sale or sharing of personal information.
- We account for the growing patchwork of US state privacy laws—including Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and Texas (TDPSA)—which grant residents access, deletion, correction, and opt-out rights.
- For contacts in the EU/EEA and UK we operate consistently with the GDPR, and for Brazilian contacts with the LGPD, supporting lawful-basis tracking and the exercise of access, rectification, and erasure rights.
- You can fulfill data-subject requests directly: contacts and their associated data can be accessed, exported in a portable format, and erased on request.
- We retain personal data only as long as needed to provide the service and meet legal obligations, and suppression-list entries are retained specifically to honor prior opt-outs and prevent re-contact.
Sub-Processors & Data Handling
We rely on a small set of vetted US-based sub-processors, each engaged for a specific function, and we make our data-processing terms available to customers who need them.
- Amazon Web Services (AWS SES and supporting AWS services): email delivery and infrastructure hosting in US regions.
- Supabase (managed PostgreSQL): primary application database and storage, secured with encryption at rest and Row-Level Security.
- Stripe: payment processing and subscription billing; Stripe is a PCI-DSS Level 1 certified provider, and Mailmundo does not store full card numbers.
- A Data Processing Addendum (DPA) covering our handling of personal data is available to customers on request, and we maintain a current list of sub-processors that we will update as our vendors change.
Compliance Posture & Roadmap
We are transparent about which assurances are in place today versus those still on our roadmap, and we will never claim a certification we do not hold.
- Mailmundo is NOT currently SOC 2 certified. A SOC 2 program is on our roadmap and in progress; we will publish the report only once an independent audit is complete.
- Today our posture rests on concrete, verifiable controls—encryption in transit and at rest, RLS tenant isolation, hashed API keys, MFA, and a hash-chained audit log—rather than on certifications we have not yet earned.
- We operate as a US LLC subject to US federal and state law, including FTC enforcement of CAN-SPAM and state attorneys-general enforcement of US privacy statutes.
- We continuously review our controls against recognized frameworks (such as the SOC 2 Trust Services Criteria) and will update this page as our compliance posture matures.
Incident Response & Breach Posture
We maintain a defined process for detecting, containing, and communicating about security incidents, and we comply with applicable US breach-notification obligations.
- We monitor our systems for anomalous activity and maintain an internal incident-response process to triage, contain, and remediate security events.
- In the event of a breach involving personal information, we will notify affected customers and any required regulators in accordance with applicable US state breach-notification laws (which exist in all 50 states) and any contractual commitments.
- Our hash-chained audit log and access controls support forensic review by making unauthorized changes to sensitive records detectable.
- We maintain backups and recovery procedures so that we can restore service and data integrity following an incident.
Responsible Disclosure & Security Contact
We welcome reports from security researchers and the public, and we commit to handling them in good faith.
- If you believe you have found a vulnerability, please report it to security@mailmundo.com with enough detail for us to reproduce the issue.
- We ask researchers to act in good faith—avoid privacy violations, data destruction, and service disruption—and to give us a reasonable opportunity to remediate before public disclosure.
- We will acknowledge legitimate reports, investigate promptly, and keep reporters informed of remediation progress.
- We do not pursue legal action against researchers who follow responsible-disclosure practices and these guidelines.
This page describes Mailmundo's security and compliance practices for informational purposes and is provided 'as is' without warranty. It is not legal advice and does not create any contractual or legal obligation; the governing terms are those in your Mailmundo agreement. Statements about applicable laws (including CAN-SPAM, CCPA/CPRA and other US state privacy laws, GDPR, and LGPD) are general summaries and may not reflect every requirement applicable to your specific use. You are responsible for your own compliance, including obtaining consent where required and providing accurate sender information. Mailmundo is not SOC 2 certified; any reference to SOC 2 reflects a roadmap initiative that is in progress and not yet audited. Sub-processors, controls, and practices may change, and we will update this page accordingly.