Deliverably
Features FAQs About Contact Join waitlist
Join waitlist

Legal

Security Policy

Last updated: August 2026

Privacy Terms DPA Refunds Cookies Security

This Security Policy describes the technical and organizational measures Deliverably (“Deliverably,” “we,” “us,” or “our”) uses to protect the Deliverably websites, console, and Customer Content.

It supplements our Privacy Policy, Terms of Service, and Data Processing Addendum. It is a public summary for customers and prospects — not a penetration-test report or certification claim unless we separately publish one.

Contact: privacy@deliverably.co · legal@deliverably.co
Security reports: privacy@deliverably.co (include “Security” in the subject)
Last updated: August 2026


1. Scope

This Policy covers:

  • The hosted console (for example, console.deliverably.co)
  • Supporting infrastructure we operate for Radar, Clarity, Email Validation, and Inbox Testing
  • Customer Content processed in those Services

It does not cover your own ESP, DNS host, Google/Microsoft accounts, or other systems outside Deliverably’s control.


2. Security principles

We design and operate the Services with these goals:

  1. Confidentiality — limit access to Customer Content to authorized systems and personnel
  2. Integrity — protect against unauthorized alteration
  3. Availability — keep core Services running and recoverable within practical limits
  4. Least privilege — grant only the access needed for a role or workload
  5. Defense in depth — combine network, application, identity, and operational controls

Where GDPR Article 32 applies, we implement measures appropriate to the risk, taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing.


3. Infrastructure and hosting

  • Primary production workloads run on Amazon Web Services (AWS) in us-east-1 (United States).
  • We use managed services (for example, compute, databases, object storage, queues, and edge delivery) consistent with our architecture.
  • Public endpoints are served over TLS (HTTPS).
  • Object storage for sensitive capture paths (for example, inbox and DMARC inbound) uses lifecycle rules to expire data on short schedules where product design requires it.

4. Application security

  • Authentication for the console via credentials and, where enabled, Google OAuth
  • Session management designed to keep authenticated users associated with their workspace
  • Workspace isolation at the application data-model layer (org-scoped queries and entitlements)
  • Input handling and authorization checks on API / job paths
  • Private preview gate cookie where an environment is password-protected before login

5. Encryption

  • In transit: TLS for public web and API traffic
  • At rest: encryption provided by cloud infrastructure defaults for managed databases and object storage where enabled by the platform

6. Access control (Deliverably personnel)

  • Access to production systems is limited to personnel who need it to operate, support, or secure the Services
  • Access is subject to confidentiality obligations
  • We use cloud identity and least-privilege patterns for operational access
  • Customer support access to Customer Content is limited to what is needed to resolve a request you initiate

7. Logging, monitoring, and abuse prevention

  • Application and infrastructure logs for reliability, security, and abuse detection
  • Job and queue monitoring for background processing
  • Retention of operational logs is limited (typically on the order of 30–90 days unless a longer period is needed for an investigation)

8. Data retention aligned to product risk

Examples (see Privacy Policy for the full schedule):

Data Typical retention
Inbox Testing captures / previews ~24 hours
Raw DMARC RUA objects ~30 days
Radar observation history ~90 days (unless longer monitoring history applies)
Validation / Clarity content Life of workspace unless deleted earlier

Shorter retention for high-sensitivity capture paths reduces breach impact.


9. Subprocessors and vendors

  • We use vetted cloud and SaaS providers (hosting, email transport, payments, AI analysis APIs, OAuth/reputation integrations).
  • Material subprocessors are bound by contractual data-protection terms no less protective than our DPA where they process Customer Personal Data.
  • A public subprocessors list will be published at [SUBPROCESSORS_URL] (or provided on request).

10. Artificial intelligence

  • AI features (for example, Clarity analysis) may send necessary content to configured AI providers to deliver the feature you requested.
  • We do not use Customer Personal Data to train Deliverably’s own general-purpose AI models (see DPA Section 4).

11. Vulnerability management and change

  • Dependency and platform updates on a practical cadence
  • Review of significant infrastructure and application changes before production deployment
  • Separation of configuration/secrets from application source where feasible

12. Incident response

If we become aware of a Personal Data Breach affecting Customer Personal Data:

  1. We investigate and contain the issue
  2. We notify affected customers without undue delay (and within 24 hours where feasible), as described in the DPA
  3. We cooperate on remediation and required regulatory or data-subject notifications you must make

Report suspected security issues to privacy@deliverably.co with enough detail for us to reproduce or investigate. Please do not publicly disclose vulnerability details until we have confirmed a fix or coordinated disclosure.


13. Customer responsibilities

You are responsible for:

  • Protecting account credentials and OAuth connections
  • Configuring alert webhooks and treating webhook URLs as secrets
  • Lawful use of email lists and campaign content you upload
  • Keeping DNS, ESP, and third-party integrations you control secure
  • Exporting data you need before deletion or plan cancellation

14. No absolute guarantee

No system is perfectly secure. This Policy describes measures we implement in good faith; it does not create an SLA, warranty, or guarantee against all unauthorized access, loss, or interruption beyond commitments in your Agreement.


15. Changes

We may update this Security Policy as our architecture and controls evolve. Material changes will be reflected by updating the “Last updated” date and, where appropriate, customer notice.


16. Contact

Privacy / security: privacy@deliverably.co
Legal: legal@deliverably.co


© 2026 Deliverably. All rights reserved.

© 2026 Deliverably. All rights reserved. legal@deliverably.co

For legal inquiries, contact legal@deliverably.co. Privacy requests: privacy@deliverably.co.

Deliverability process made simple.

Features Privacy Terms Cookies Legal Contact