Security and privacy

Security controls you can evaluate.

Elite Mail Suite documents what is implemented, what data each workflow needs, and where independent certification is not currently claimed.
Request security informationRead the DPA

Implemented controls

Security across the account, workspace, and service

Account access

Hashed credentials, optional authenticator MFA, device management, short-lived installation tokens, and rotating refresh credentials.

Tenant and team boundaries

Tenant-scoped APIs and role-based team permissions keep workspace access tied to an authenticated account and approved role.

Transport and service hardening

TLS in transit, rate limits, hardened non-root services, least-privilege service accounts, and security-focused response headers.

Recovery

SQLite integrity checks, backup procedures, and restore-readiness checks make recoverability an operating requirement rather than a policy sentence.

Auditability

Security and administrative actions produce audit history so teams can review sensitive changes and access-related events.

Data minimization

Standard tracking sends message metadata rather than message bodies. Stored content and files enter the suite through deliberate product workflows.

Data practice

Collect the signal needed for the workflow—not the entire inbox.

  1. 1Standard tracking records normalized message, recipient, delivery, and event metadata. Message bodies are not part of the standard tracking payload.
  2. 2Explicit workflows store the templates, campaign content, recordings, documents, and signature material a user chooses to create or upload.
  3. 3Signal classification keeps likely-human, privacy-protected, automated scanner, sender, and unknown activity distinct rather than manufacturing certainty.
  4. 4Retention and deletion are described in the privacy policy and DPA, including separate treatment for network and approximate-location fields.

Assurance status

Precise about the evidence available today

These controls are not a claim of SOC 2, ISO 27001, or another independent certification. Enterprise evaluators may request current architecture, access-control, recovery, and vulnerability-management information under appropriate confidentiality terms.

Report a suspected vulnerability privately

Use the support contact and include enough detail to reproduce the issue. Do not access other users’ data, disrupt the service, or perform destructive testing. Credible reports are acknowledged and coordinated through remediation and disclosure.

Contact security