This document is a working draft prepared by EmailRoute and is pending review by qualified legal counsel.
Our practices
- Encryption of traffic in transit.
- Secure authentication, with optional two-factor authentication.
- Role-based access control for staff and administrators.
- API keys stored as hashes; secrets shown only once at creation.
- Restricted administrative access with audit logging of sensitive actions.
- Rate limiting on public endpoints.
- Monitoring and incident response processes.
We do not publish details of internal infrastructure.
Reporting a vulnerability
We welcome responsible disclosure. Email security@companymailroute.com with a description and reproduction steps. Please do not access other customers' data, degrade the service, or disclose the issue publicly before we have responded.