Security

Security, trust, and procurement posture

A conservative, operator-friendly summary of how InvocaboMail handles access, data, auditability, and recovery.

Developers
No-send postureSecurity and trust review pages are informational only. They do not enable outbound email or provider mutation.

Encryption

Secrets and mailbox credentials are handled server-side. Sensitive values should never be displayed back to the browser.

Access control

Workspace-aware permissions gate campaign, mailbox, and Graph management actions.

Auditability

Readiness, inbox review, and suppression workflows keep operator-visible traces without enabling live sends.

Incident response

No-send guardrails, review queues, and health dashboards make it possible to investigate before enabling outbound behavior.

Vendor risk

Keep procurement-sensitive details visible in one place and avoid hidden behavior in critical flows.

Trust-center notes

Conservative claims only
  • SOC-style control posture should be reflected only when actually verified.
  • GDPR and data-processing claims should stay conservative and documented.
  • Any future Trust Center should be linked from here once it exists.
  • Security reviews should not require reading source code to understand the control model.

Related surfaces