Security at Postline
Implemented controls and current limitations. Postline does not claim SOC 2 Type II certification or end-to-end email encryption.
Report a security issueImplemented controls
- TLS for supported external HTTP and SMTP submission paths
- Hashed, scoped, expiring API keys with optional IP allowlists
- Separate test and live key prefixes
- Hashed SMTP credentials isolated from dashboard access
- DKIM signing and DNS checks for SPF and DMARC alignment
- Global project-level suppression checks before queueing
- Webhook HMAC signatures, timestamps, unique event IDs, bounded retries, and SSRF-resistant delivery
- Transactional and marketing queue separation
- Passwordless dashboard login with hashed one-time codes and hashed session tokens
Encryption boundary
TLS is transport encryption, not end-to-end email encryption. Recipient providers can process delivered content. Customers needing message-level confidentiality must add an appropriate scheme such as S/MIME, PGP, or application-layer encryption.
Assurance status
No SOC 2 Type II report is currently advertised. Security controls remain subject to tenant-isolation testing, operational review, and customer-specific due diligence.
Report a vulnerability
Send a minimal reproduction and impact assessment to security@srs-postline.com. Do not access other customers' data, disrupt service, or publish an unresolved issue without coordination.