Legal Center

Security Policy

Version 1.0 · Effective 2026-08-19

This document is a working draft prepared by EmailRoute and is pending review by qualified legal counsel.

Our practices

  • Encryption of traffic in transit.
  • Secure authentication, with optional two-factor authentication.
  • Role-based access control for staff and administrators.
  • API keys stored as hashes; secrets shown only once at creation.
  • Restricted administrative access with audit logging of sensitive actions.
  • Rate limiting on public endpoints.
  • Monitoring and incident response processes.

We do not publish details of internal infrastructure.

Reporting a vulnerability

We welcome responsible disclosure. Email security@companymailroute.com with a description and reproduction steps. Please do not access other customers' data, degrade the service, or disclose the issue publicly before we have responded.