Trust center

Security, privacy and reliability

This page is maintained by Imapost to answer common security and privacy questions. It describes current controls and practices — it is not an independent certification.

Access & authentication

Email + Google SSO, role-based access control, session revocation and per-workspace audit logs.

Data encryption

TLS 1.2+ in transit. Data at rest encrypted by our managed cloud database. Social OAuth tokens encrypted with AES-256-GCM before storage.

Platform & hosting

Deployed on a global CDN with 99.9% uptime target. Managed database, storage and background workers.

Privacy & data use

We do not sell your data or train foundation models on your content. See our privacy policy for details on lawful bases and retention.

Subprocessors & integrations

Every integration uses official OAuth. See the subprocessor list on request; we notify customers of material changes.

Retention & deletion

Content and analytics deleted on request from the account owner. Backups purged on standard rotation.

Report a vulnerability

Found a security issue? Email security@imapost.com with reproduction steps. We acknowledge within 24 hours and coordinate disclosure.

Certification and compliance program status is available on request for enterprise buyers. Nothing on this page constitutes a certification.