Airmail

Security at Airmail

Airmail uses tenant-scoped authorization, protected credentials, verified domains and controlled activation. This page describes current technical controls, not a certification.

Account and API access

Customer sessions use secure, HttpOnly cookies in production, CSRF protection and persistent revocation. Operator authentication is separate from customer authentication. API keys are hashed at rest and their raw value is shown once.

Tenant isolation

Domains, keys, messages, usage and suppressions are resolved through the authenticated workspace and tenant. Cross-tenant object reads fail closed.

Sending authorization

New tenants remain pending. Email verification, domain ownership, DNS authentication, onboarding review and activation gates prevent a signup from becoming unrestricted sending access.

Data handling

Airmail processes sender and recipient addresses, message content and delivery lifecycle data to provide email transport. Do not send secrets or unnecessary sensitive data in message metadata. No compliance certification is claimed.

Report a concern

Closed-beta security concerns are handled directly by the Airmail operator. Include a safe msg_* ID and approximate timestamp; never send an API key.