For an email tool, security is the product.
The technical and organizational measures behind EmailListChecker — SOC 2 Type II, AES-256 at rest, TLS 1.2+ in transit, least-privilege access, pen testing, and an incident-response plan that actually gets exercised.
01Our security program
For an email tool, security is the product. This document describes the technical and organizational measures (TOMs) EmailListChecker maintains to protect your account and the contacts you submit. It is referenced by our DPA and SaaS Agreement and is reviewed at least annually.
We maintain a SOC 2 Type II program and align to GDPR. Our report is available under NDA for due diligence. SOC 2 Type II GDPR Google Security assessed
02Encryption
- In transit: TLS 1.2 or higher for all connections to the app and API; HSTS enforced; modern cipher suites only.
- At rest: AES-256 encryption for stored data, including uploaded lists, results, and backups.
- Key management: keys managed in a dedicated key management service with rotation and strict access controls.
03Access control
- Least privilege — staff get the minimum access needed, granted just-in-time and reviewed regularly.
- SSO & MFA required for all internal systems.
- Audited admin actions — privileged operations are logged and monitored.
- Customer controls — your own SSO, role-based access, and API key scoping on eligible plans.
04Network & infrastructure
The Service runs on hardened cloud infrastructure with network isolation, security groups, and segmented environments. We patch promptly, use infrastructure-as-code for repeatable, reviewed changes, and separate production from development and staging.
Enterprise and API customers can process addresses in memory with zero retention — nothing about the submitted address is written to disk.
05Monitoring & testing
- Continuous logging and monitoring with alerting on anomalous activity.
- Regular third-party penetration testing and ongoing vulnerability scanning.
- Secure SDLC: code review, dependency scanning, and secrets detection in CI.
- A coordinated vulnerability disclosure channel for researchers.
06Resilience & availability
We target 99.9% uptime with redundancy across availability zones, automated backups, and tested restore procedures. Disaster-recovery objectives (RPO/RTO) are documented and exercised. Our status page publishes incidents and maintenance windows.
07People & vendors
Personnel are background-checked where lawful, bound by confidentiality, and trained on security and privacy at onboarding and annually. Sub-processors are vetted and bound by data-protection terms no less protective than ours — the current list is in our GDPR document.
08Incident response
We maintain a documented incident-response plan with defined roles, severity tiers, and runbooks. On a confirmed personal-data breach affecting your data, we notify you without undue delay with the facts you need to meet your own obligations, and we conduct a post-incident review to prevent recurrence.
09Security contact
For security questions, our SOC 2 report, or to report a vulnerability, contact [email protected]. We respond to credible security reports promptly.
EmailListChecker, Inc. · Security team: [email protected] · SOC 2 Type II report available under NDA.