Security

Last updated: 1 October 2026

What Mailbase does today to protect accounts, data and sending reputation — described from the product, with no promise beyond it.

1. Signing in

  • There is no password to steal: you sign in with a Google account or with a one-time link sent to your email.
  • Two-factor authentication (an authenticator app, time-based codes) can be turned on for any user. Ten single-use recovery codes are issued, and only their hashes are stored. Once it is on, a session is not fully authorised until the second factor has been given.
  • Sessions are stored in the database, so they can be revoked server-side.

2. Who can do what

Access inside a workspace is role-based: owner, admin, member, sender, developer, billing and viewer. Sending, team management, billing, developer settings and audit logs each require the matching permission, and a viewer can only read. Every workspace is isolated from the others: data is always read through the workspace it belongs to.

3. Audit log

Workspace actions that matter are recorded in an audit log that owners, admins and developers can read. Actions taken by Mailbase operators on the platform console — settings, models, screening rulings, pausing a workspace — are recorded in a separate operator trail.

4. Secrets and encryption

  • Credentials Mailbase must reuse — AI provider keys and tokens, connected mailbox credentials, a workspace's own sending credentials, two-factor secrets, and secret platform settings — are encrypted at rest with AES-256-GCM before they are stored.
  • API tokens are stored only as SHA-256 hashes; the token is shown once, when it is created.
  • Stored secrets are never sent back to the browser: the interface shows a short hint (the last characters) and nothing more.
  • The site is served over HTTPS with HTTP Strict Transport Security, a content security policy and the usual hardening headers.

5. Where email goes

Mail sent through Mailbase's managed sending goes through Amazon SES in the Ireland region (eu-west-1). Delivery, bounce and complaint events come back through signed notifications that Mailbase verifies before acting on them. Workspaces can instead connect their own sending account. The full list of services that touch personal data is on the sub-processors page.

6. Your data, in your hands

  • Export: a user can export their account data, and a workspace can export its data.
  • Erasure: deleting a workspace deletes its data, and a durable receipt with no personal data proves it was done. Erasing a single contact removes their personal data but keeps a minimal suppression record so they are never contacted again.
  • Objection: every prospecting email carries a one-click unsubscribe; see the GDPR page.

7. Abuse controls

A shared sending platform is only as good as its worst sender, so abuse is handled before and after sending:

  • Outgoing email is screened for scams and phishing before it leaves; uncertain messages are held for a person to review.
  • Bounce and complaint rates are watched per workspace and across the whole platform; a workspace that crosses the line is paused automatically.
  • Recipients who unsubscribed, bounced or complained are never mailed again; sending volume is capped, and new domains warm up gradually.
  • API and application requests are rate-limited per user, per token and per workspace.

8. What this page does not claim

Mailbase does not claim any security certification or audit report, and this page describes the product, not a guarantee. To report a vulnerability or ask a security question, write to contact@mailbase.studio or use the contact form.