Security at COLDPOST
Enterprise-grade controls protect your data and your sending reputation at every layer.
Certifications and compliance
COLDPOST is independently audited and built to meet the standards enterprise security teams expect.
How we protect your data
Encryption everywhere
Data is encrypted in transit with TLS 1.2+ and at rest with AES-256.
Access controls
Least-privilege access, SSO/SAML, and SCIM provisioning on Enterprise.
Isolation
Logical tenant isolation keeps every customer’s data strictly separated.
Monitoring
Continuous logging, anomaly detection, and 24/7 alerting on our infrastructure.
Backups & recovery
Automated encrypted backups with tested restore procedures.
Secure SDLC
Code review, dependency scanning, and regular third-party penetration tests.
Infrastructure
COLDPOST runs on hardened cloud infrastructure in SOC 2 and ISO 27001 certified data centers, with network segmentation, managed firewalls, and DDoS protection.
Reliability
We design for high availability with redundancy across availability zones. Our public status page reports uptime and incidents in real time.
Enterprise customers can request a custom uptime SLA, security questionnaire support, and a signed DPA.
Responsible disclosure
We welcome reports from security researchers. If you believe you have found a vulnerability, email security@coldpost.com. We investigate every report and will not pursue researchers acting in good faith.