Security
Security at Mailchk
We take security seriously. Here's how we protect your data and our systems.
Encryption in Transit
All data is encrypted using TLS 1.3 during transmission. We enforce HTTPS for all API endpoints and web traffic.
Encryption at Rest
Sensitive data stored in our systems is encrypted using AES-256 encryption.
No Email Storage
We do not store the email addresses you validate. Data is processed in memory and immediately discarded.
Secure API Keys
API keys are hashed and salted. You can rotate keys at any time from your dashboard.
Access Controls
We implement strict role-based access controls for all internal systems and customer data.
Regular Audits
We conduct regular security audits and penetration testing to identify and address vulnerabilities.
Infrastructure Security
Cloudflare Edge Network
Our API runs on Cloudflare's global edge network, providing DDoS protection, WAF (Web Application Firewall), and automatic SSL/TLS certificate management. Traffic never touches our origin servers for validation requests.
SOC 2 Compliance
We are working towards SOC 2 Type II certification to demonstrate our commitment to security, availability, and confidentiality. Our infrastructure providers (Cloudflare) maintain SOC 2, ISO 27001, and other certifications.
Incident Response
We have a documented incident response plan that includes detection, containment, eradication, and recovery procedures. Security incidents are communicated to affected customers within 72 hours of discovery.
Report a Vulnerability
Found a security issue? We appreciate responsible disclosure. Please report vulnerabilities to our security team.
security@mailchk.io