Security

Security You Can Trust

Your data security is our top priority. We use industry-leading practices to protect your information and earn your trust every day.

SOC 2 Type II

Security, availability, and confidentiality

GDPR

EU data protection compliance

CCPA

California consumer privacy

HIPAA Ready

Available for Enterprise plans

Our Security Practices

Comprehensive security measures to protect your data at every level.

Encryption at Rest & in Transit

All data is encrypted using AES-256 at rest and TLS 1.3 in transit. Your email content and tracking data are always protected.

SOC 2 Type II Certified

We have completed SOC 2 Type II certification, demonstrating our commitment to security, availability, and confidentiality controls.

GDPR Compliant

We comply with GDPR requirements including data minimization, right to access, right to deletion, and data processing agreements.

Two-Factor Authentication

Protect your account with 2FA using authenticator apps or SMS. Available on all plans at no extra cost.

We Never Read Your Emails

InboxPilot processes tracking metadata only. We never read, store, or analyze the content of your emails. Period.

Infrastructure Security

Hosted on SOC 2 certified cloud infrastructure with redundant systems, automated backups, and 99.9% uptime SLA.

Minimal Data Collection

We collect only the data necessary to provide our service. No email content, no message bodies, no attachment contents.

Regular Security Audits

We conduct annual third-party penetration tests and continuous vulnerability scanning to identify and fix security issues.

Incident Response

We maintain a documented incident response plan and will notify affected users within 72 hours of any data breach.

What We Do & Don't Collect

What We Collect

  • Email open/click timestamps
  • Recipient engagement metadata
  • Document view analytics
  • Account and billing info

What We Never Collect

  • Email message content or body
  • Attachment file contents
  • Contact list data (beyond tracking)
  • Browsing history or personal data

Questions about security?

We are happy to answer any security questions or provide our SOC 2 report upon request.

Contact Security Team