For an email tool, security is the product.
The technical and organizational measures behind EmailListChecker — TLS for data in transit, least-privilege access, availability monitoring, and breach notification.
01Our security program
For an email tool, security is the product. This document describes the technical and organizational measures (TOMs) EmailListChecker maintains to protect your account and the contacts you submit. It is referenced by our DPA and SaaS Agreement and is reviewed at least annually.
These measures support our obligations under GDPR. GDPR
02Encryption
- In transit: TLS 1.2 or higher for all connections to the app and API; HSTS enforced; modern cipher suites only.
- Key management: keys managed in a dedicated key management service with rotation and strict access controls.
03Access control
- Least privilege — staff get the minimum access needed, granted just-in-time and reviewed regularly.
- SSO & MFA required for all internal systems.
- Audited admin actions — privileged operations are logged and monitored.
- Customer controls — your own SSO, role-based access, and API key scoping on eligible plans.
04Network & infrastructure
The Service runs on hardened cloud infrastructure with network isolation, security groups, and segmented environments. We patch promptly, use infrastructure-as-code for repeatable, reviewed changes, and separate production from development and staging.
Enterprise and API customers can process addresses in memory with zero retention — nothing about the submitted address is written to disk.
05Monitoring & testing
- Automated availability checks of monitored public endpoints, with email alerts to our team when a check fails.
06Resilience & availability
Backups are scheduled daily.
07People & vendors
Personnel are background-checked where lawful, bound by confidentiality, and trained on security and privacy at onboarding and annually. Sub-processors are vetted and bound by data-protection terms no less protective than ours — the current list is in our GDPR document.
08Incident response
If we become aware of a personal-data breach affecting personal data we process for you, we notify you without undue delay and provide the information reasonably available to help you meet your own notification obligations.
09Security contact
Security questions and vulnerability reports can be sent to [email protected]. We respond to credible security reports promptly.
EmailListChecker, Inc. · Security contact: [email protected]