Chain of custody.
Email is a trust business. This page explains where your data lives, how it's protected, and who touches it, in plain language. For what we collect and why, see the privacy policy.
The sorting office
Where your email is processed
Email delivery runs in the EU. Mail sent through Postboi is delivered by Amazon SES from the eu-north-1 region (Stockholm, Sweden), and message content is processed and delivered from there. The application itself (dashboard and API) runs on Cloudflare Workers, which execute on Cloudflare's global edge network close to whoever's making the request, with account data stored in Cloudflare D1.
We're a UK-operated service, and our processing is governed by UK GDPR. If you need a data processing agreement for your own compliance, email support@postboi.app.
The seal
Encryption
Encryption · in transit and at rest
- Browser to dashboard
- TLS
- Your app to the API
- TLS
- Onward to recipient mail servers
- opportunistic TLS As SMTP allows
- Stored data
- encrypted at rest By Cloudflare and AWS
The keys
SealedKeys and credentials
- API keys are stored as one-way hashes. We can't read a key back after creation. If one leaks, revoke it and mint another in the dashboard.
- No passwords. Sign-in is by magic link or SSO (Google, Microsoft, GitHub), so there's no password database to breach.
- Card details never touch our servers. Payment is handled end-to-end by Stripe.
- Synced provider credentials are sealed, and used server-side for exactly three things. Credentials your team syncs for
postboi syncare AES-GCM-encrypted at rest, and decrypted only (1) to poll your provider for delivery events when it can't push webhooks (SMTP, Microsoft 365, Cloudflare), on by default when such a credential is synced, pausable per provider from the credentials page; (2) to send on your behalf when you have turned on send via there; and (3) to verify the delivery-event webhooks of a provider you have pointed at us, using its signing secret, and, when you press Register on that page, to ask that provider to point its webhooks here, storing any signing key it hands back. Never otherwise.
One bag each
Sending isolation
Every account sends under its own isolated sending identity with per-account bounce and complaint tracking. An account whose sending turns abusive is paused automatically, which means one bad actor can't burn the deliverability of your mail. Suppression lists, rate limits and daily caps back that up.
The letterbox
Form endpoints
Hosted form submissions are spam-checked (honeypot, and optionally a managed captcha) before anything is sent, rate-limited per form, and can only deliver to a verified team member's email address. A public form URL can never be pointed at an arbitrary inbox.
Subprocessors
Subprocessors
The full list of companies that process data on our behalf:
Subprocessors · the whole list
- Amazon Web Services
- email delivery SES, eu-north-1
- Cloudflare
- hosting, storage, captcha Workers, D1, R2, Turnstile
- Stripe
- payments and billing
- Google Analytics
- site analytics Only with cookie consent
That's the whole list. We'll update this page before adding to it.
Found something?
Reporting a vulnerability
Found something? Email support@postboi.app with details and we'll respond quickly, usually the same day. Please give us a reasonable window to fix before disclosing publicly, and don't test against other people's accounts or data. We're grateful to anyone who reports in good faith.
The machine-readable version of this is at /.well-known/security.txt.
The board
Status
Live service health is published at postboi.app/status, checked against the real dependencies every time the page loads.
ALSO The rest of the small print
- PB-01 What we keep, and what we don't. What we collect, who touches it, and how to get it back. Privacy policy
- PB-02 Conditions of carriage. The rules of sending through Postboi, and what happens when they're broken. Terms of service
- PB-04 Every lane is open. Live checks against the real dependencies, every time the page loads. Service status
- PB-05 Rates of postage. Every plan and what a month costs at your volume, in plain figures. Pricing
- PB-06 Postboi or Resend? Setup, price at every volume, and what comes in the box, side by side. Comparison
- PB-07 Time in transit. How fast our mail reaches each inbox provider, and our uptime, from our own figures. Delivery record