Mailchk

Security

Security at Mailchk

We take security seriously. Here's how we protect your data and our systems.

Encryption in Transit

All data is encrypted using TLS 1.3 during transmission. We enforce HTTPS for all API endpoints and web traffic.

Encryption at Rest

Sensitive data stored in our systems is encrypted using AES-256 encryption.

No Email Storage

We do not store the email addresses you validate. Data is processed in memory and immediately discarded.

Secure API Keys

API keys are hashed and salted. You can rotate keys at any time from your dashboard.

Access Controls

We implement strict role-based access controls for all internal systems and customer data.

Regular Audits

We conduct regular security audits and penetration testing to identify and address vulnerabilities.

Infrastructure Security

Cloudflare Edge Network

Our API runs on Cloudflare's global edge network, providing DDoS protection, WAF (Web Application Firewall), and automatic SSL/TLS certificate management. Traffic never touches our origin servers for validation requests.

SOC 2 Compliance

We are working towards SOC 2 Type II certification to demonstrate our commitment to security, availability, and confidentiality. Our infrastructure providers (Cloudflare) maintain SOC 2, ISO 27001, and other certifications.

Incident Response

We have a documented incident response plan that includes detection, containment, eradication, and recovery procedures. Security incidents are communicated to affected customers within 72 hours of discovery.

Report a Vulnerability

Found a security issue? We appreciate responsible disclosure. Please report vulnerabilities to our security team.

security@mailchk.io