How we protect your email, data, and infrastructure.
Security is foundational to NBXTD Mail. As an email infrastructure provider, we understand that our customers entrust us with sensitive communications. We implement defense-in-depth security measures across our application, infrastructure, and operations to protect your data from unauthorized access, disclosure, alteration, and destruction.
All data transmitted between your browser and our servers is encrypted using TLS 1.2+. Email content and stored data are encrypted at rest using industry-standard AES-256 encryption.
Resend API keys, webhook secrets, and other credentials are stored as encrypted environment variables and are never exposed in client-side code, logs, or databases.
Access to administrative functions is restricted by role. Organization admins control who can send, receive, delete, forward, or manage rules for each mailbox.
Every user and system action — sends, deletes, configuration changes, and access events — is recorded with timestamps, IP addresses, and entity-level details for compliance and forensic analysis.
Our email infrastructure runs on vetted cloud providers with network segmentation, firewalls, and automated security patching. We use Resend for email delivery, which maintains SOC 2 compliance.
We monitor for suspicious activity, unauthorized access attempts, and abuse patterns. Anomalous behavior triggers automated alerts and may result in temporary account suspension for protection.
We enforce SPF, DKIM, and DMARC verification for all sending domains to prevent email spoofing and phishing. Domains cannot send email until DNS records are verified.
Sessions are secured with signed tokens and configurable timeout policies. Multi-factor authentication is supported for sensitive operations.
Email Content: Your email messages and attachments are stored securely and are only accessible to authorized users within your organization. We do not read, scan, or use your email content for advertising purposes.
AI Processing: AI-powered features process your email content to generate summaries, categories, and draft replies. This processing is performed securely and is not shared with third parties or used to train external models.
Data Retention: Data is retained according to your account settings and our Privacy Policy. Deleted data is purged within 30 days of deletion, except where retention is legally required.
Backups: Data is backed up regularly with encrypted backups stored in geographically separated locations to ensure availability and disaster recovery.
Our security practices align with industry frameworks and regulations including:
We maintain an incident response plan to identify, contain, and remediate security incidents. In the event of a confirmed data breach affecting your information, we will:
We welcome security researchers to report vulnerabilities responsibly. If you discover a security issue, please email us at help@nbxtd.com with a detailed description. We ask that you do not publicly disclose vulnerabilities until we have had a reasonable time to address them. We acknowledge all legitimate reports and work to remediate confirmed issues promptly.
For security-related questions, concerns, or reports, please contact us at help@nbxtd.com or through our Contact page. We are committed to maintaining the trust you place in us to protect your email infrastructure.
Join the next generation of businesses running email on their own terms. Custom domains, AI assistance, and enterprise-grade delivery — all in one dashboard.