Security

Security at Postline

Implemented controls and current limitations. Postline does not claim SOC 2 Type II certification or end-to-end email encryption.

Report a security issue

Implemented controls

  • TLS for supported external HTTP and SMTP submission paths
  • Hashed, scoped, expiring API keys with optional IP allowlists
  • Separate test and live key prefixes
  • Hashed SMTP credentials isolated from dashboard access
  • DKIM signing and DNS checks for SPF and DMARC alignment
  • Global project-level suppression checks before queueing
  • Webhook HMAC signatures, timestamps, unique event IDs, bounded retries, and SSRF-resistant delivery
  • Transactional and marketing queue separation
  • Passwordless dashboard login with hashed one-time codes and hashed session tokens

Encryption boundary

TLS is transport encryption, not end-to-end email encryption. Recipient providers can process delivered content. Customers needing message-level confidentiality must add an appropriate scheme such as S/MIME, PGP, or application-layer encryption.

Assurance status

No SOC 2 Type II report is currently advertised. Security controls remain subject to tenant-isolation testing, operational review, and customer-specific due diligence.

Report a vulnerability

Send a minimal reproduction and impact assessment to security@srs-postline.com. Do not access other customers' data, disrupt service, or publish an unresolved issue without coordination.