InboxPilot
TRUST & COMPLIANCE

Security You Can Trust

Your data security is our top priority. We use industry-leading encryption, strict role-based access, and zero-payload storage to protect your workspace.

SOC 2 Type II

Readiness controls documented

GDPR Compliant

Privacy request workflows

CCPA Compliant

Consumer privacy workflows

Enterprise DPA

Data processing terms available

ARCHITECTURE

Our Security Practices

Comprehensive security measures designed to protect your data at every layer.

Encryption at Rest & in Transit

All data is encrypted using AES-256 at rest and TLS 1.3 in transit. Your email metadata and tracking streams are always protected.

SOC 2 Readiness

Security, availability, and confidentiality controls are documented for audit readiness. Formal certification status will be published after completion.

Privacy Rights Workflows

GDPR and CCPA support paths include data minimization, access exports, deletion workflows, and documented processing practices.

Secure Authentication

Accounts use OAuth 2.0 PKCE or hashed password authentication with signed JWT sessions, refresh-token rotation, and secret validation.

We Never Read Your Emails

InboxPilot processes tracking metadata only. We never read, store, or analyze the body or attachments of your messages. Period.

Infrastructure Security

Production deployment uses managed cloud infrastructure, isolated service credentials, health checks, and documented backup and rollback procedures.

Minimal Data Collection

We collect only the data necessary to provide our service. No email content, no message bodies, no attachment contents.

Security Review Process

Dependency audits, CI checks, and vulnerability scanning are built into release gates. External penetration testing remains a launch requirement.

Incident Response

We maintain a documented incident response plan and will notify affected users within 72 hours of any security event.

DATA BOUNDARIES

What We Do & Don't Collect

Clear privacy boundaries with zero message body retention.

What We Collect

  • Email open and link click timestamps
  • Recipient engagement telemetry (device/city)
  • Document view analytics and page durations
  • Workspace user account credentials & billing info

What We Never Collect

  • Email message content, bodies, or threads
  • Attachment file payloads or raw files
  • Full contact books or unrelated address data
  • Third-party behavioral tracking or ad profiles
SECURITY INQUIRIES

Questions about security?

We are happy to answer security questions and share available security documentation under confidentiality terms.

14-day trial • No credit card required • 2-minute setup