Copper doesn’t corrode. Neither should your trust.
You are handing us your inbox, the single most sensitive system in most companies. Here is exactly what we do to deserve that, described plainly enough that your security reviewer can check it.
Encryption
TLS 1.2+ for everything in transit, HSTS enforced. AES-256 at rest for databases, object storage and backups. Keys managed in our hosting provider’s KMS with automatic rotation, in the same region as the data they protect.
Least-privilege access
Mandatory MFA on every administrative account. Role-based permissions and immediate revocation when someone leaves. Support engineers reach production Customer Data only against a specific support request from you.
Tenant isolation
Every record carries a tenant identifier enforced at the data-access layer, with automated tests that fail the build if a query can cross tenants.
Narrow mailbox scopes
OAuth scopes are limited to reading and sending mail in the mailboxes you nominate. We never request access to Drive, calendars, contacts or admin directories. Revoke access from your provider at any time.
Testing
Automated dependency and secret scanning, static analysis in CI, and peer review on every change. We have not yet commissioned an external penetration test; when we do, the summary goes to any customer who asks.
Backups and recovery
Encrypted automated daily backups, retained 30 days, running across multiple availability zones at our hosting provider. Restores are tested before we rely on them, not on a published schedule we would rather not invent.
Audit logging
Logs of every administrative and data-access action, retained 12 months and exportable by your administrators on any licence.
AI-specific controls
Prompt-injection defences, output filtering and optional PII redaction before inference. Your customers’ email is never used to train shared or third-party models: we use commercial API terms that prohibit it, and retention at the model provider is governed by that provider’s published API policy, which we link from Annex B of the DPA rather than paraphrase.
Payment scope
Card data is captured in Stripe-hosted fields and never touches our servers. That keeps us in PCI DSS SAQ A scope, the narrowest there is. We store only a token and the last four digits.
Data residency
Our default hosting region is the United States. Customers who require their Customer Data to be stored at rest in the European Union can have their workspace provisioned in our EU region (Frankfurt, Germany) at no extra cost: ask before you connect a mailbox, because we cannot move a workspace between regions afterwards. The complete list of third parties, their locations and the transfer mechanisms is in Annex B of the DPA.
Compliance posture
This is the section where most vendors put badges. We would rather set out precisely what is in place, what is not, and what is deliberately out of scope, so that a security reviewer can stop guessing and a procurement team knows before it starts.
In place today
| Item | Status |
|---|---|
| PCI DSS – SAQ A | In place, through payment fields hosted by our processor. Full card numbers never reach CopperMailer servers; we hold a token, the brand, the last four digits and the expiry. Detail on the payments page. |
| GDPR Article 28 DPA | In place, and offered to every customer including free accounts, with the Standard Contractual Clauses incorporated. Not gated behind an enterprise contract. See the DPA. |
| EU data residency | Available at no extra cost: a workspace can be provisioned in our Frankfurt region, chosen before a mailbox is connected. |
| Encryption, MFA, tenant isolation, audit logging | In place as described above: TLS 1.2+ and HSTS in transit, AES-256 at rest, mandatory MFA on administrative accounts, tenant identifiers enforced at the data-access layer, and 12 months of exportable audit log on every licence. |
| Breach notification within 72 hours | Committed contractually in clause 7 of the DPA, not just as a policy statement. |
| Responsible disclosure programme | Published, with a safe-harbour commitment and stated response times. See below. |
Not in place, and why we are saying so
Any of these could be bought as a badge. We would rather you knew the position before your review than after it.
| Item | Position |
|---|---|
| ISO/IEC 27001 | Not certified, and no audit currently scheduled. We work through the control families as a checklist, which is not the same thing, and we will not imply that it is. |
| SOC 2 Type II | Not certified, and no observation period under way. |
| External penetration test | Not yet commissioned. Planned once we are out of early access; we will publish the date here when it is booked, and not before. The summary will go to any customer who asks for it. |
| Data Protection Officer | Not appointed. We are not required to appoint one at our size and scope, so we have not invented the role. Privacy questions reach the person who actually handles them at privacy@coppermailer.com, and that person answers within one month, as the GDPR requires. |
Deliberately out of scope
| Workload | Why not |
|---|---|
| HIPAA / protected health information | Not supported. Do not route PHI through the Service; it is excluded by clause 26.4 of the Acceptable Use Policy. |
| Cardholder data inside mailboxes | Not supported. Do not route full card numbers through the Service. The PII redaction unlock masks card-like numbers as a safety net, but it is not a compliance control and we will not describe it as one. |
If your procurement process requires a SOC 2 report or an external penetration test summary, we do not have either yet, and we would rather tell you at the start of your review than at the end of it. Everything we do have – a signed DPA, a completed security questionnaire, this page – is available to any customer on request from sales@coppermailer.com.
Incident response
We run a documented incident-response plan with defined severities. If a personal data breach affects your data, we notify you without undue delay and in any event within 72 hours of becoming aware of it, with the facts we have and updates as the investigation continues, as committed in clause 7 of the DPA. We are a small team and do not staff a 24×7 rotation; incidents are worked as soon as they are detected and we will not claim a response time we cannot hold. For major incidents we publish a written post-incident review to affected customers within ten business days.
Responsible disclosure
If you have found a vulnerability, we want to hear from you and we will not send lawyers after you for telling us.
- Report to security@coppermailer.com. Our contact details and disclosure policy are published at
coppermailer.com/.well-known/security.txt. If you need to send something encrypted, ask us and we will agree a channel with you. - We acknowledge within 2 business days and give an initial assessment within 10.
- Please test only against your own account, do not access, modify or exfiltrate other customers’ data, do not run denial-of-service or spam tests, and give us reasonable time to fix an issue before disclosing it publicly.
- Researchers who follow this process act with our authorisation and we will not pursue legal action. We credit reporters who want credit, and pay discretionary bounties for high-impact findings.
- Out of scope: findings that require a compromised device, social engineering of our staff, missing best-practice headers with no demonstrable impact, and automated scanner output without a proof of concept.
Your side of the wire
Security is shared. Enable MFA on your workspace, review who has admin rights, keep auto-send restricted to topics that genuinely do not need judgement, and rotate API keys when someone leaves. We provide the controls; the configuration is yours.
Security questionnaires and a signed DPA are available to every customer, including free accounts, and we do not gate either behind an enterprise contract. Write to sales@coppermailer.com. If your procurement process requires a SOC 2 report or an external penetration test summary, we do not have one yet and would rather tell you now than at the end of your review.