Account and API access
Customer sessions use secure, HttpOnly cookies in production, CSRF protection and persistent revocation. Operator authentication is separate from customer authentication. API keys are hashed at rest and their raw value is shown once.
Tenant isolation
Domains, keys, messages, usage and suppressions are resolved through the authenticated workspace and tenant. Cross-tenant object reads fail closed.
Sending authorization
New tenants remain pending. Email verification, domain ownership, DNS authentication, onboarding review and activation gates prevent a signup from becoming unrestricted sending access.
Data handling
Airmail processes sender and recipient addresses, message content and delivery lifecycle data to provide email transport. Do not send secrets or unnecessary sensitive data in message metadata. No compliance certification is claimed.
Report a concern
Closed-beta security concerns are handled directly by the Airmail operator. Include a safe msg_* ID and approximate timestamp; never send an API key.