Back to home

Security

How we protect your email, data, and infrastructure.

Security is foundational to NBXTD Mail. As an email infrastructure provider, we understand that our customers entrust us with sensitive communications. We implement defense-in-depth security measures across our application, infrastructure, and operations to protect your data from unauthorized access, disclosure, alteration, and destruction.

Encryption in Transit and at Rest

All data transmitted between your browser and our servers is encrypted using TLS 1.2+. Email content and stored data are encrypted at rest using industry-standard AES-256 encryption.

Secure API Key Management

Resend API keys, webhook secrets, and other credentials are stored as encrypted environment variables and are never exposed in client-side code, logs, or databases.

Role-Based Access Control

Access to administrative functions is restricted by role. Organization admins control who can send, receive, delete, forward, or manage rules for each mailbox.

Comprehensive Audit Logging

Every user and system action — sends, deletes, configuration changes, and access events — is recorded with timestamps, IP addresses, and entity-level details for compliance and forensic analysis.

Infrastructure Security

Our email infrastructure runs on vetted cloud providers with network segmentation, firewalls, and automated security patching. We use Resend for email delivery, which maintains SOC 2 compliance.

Threat Detection and Monitoring

We monitor for suspicious activity, unauthorized access attempts, and abuse patterns. Anomalous behavior triggers automated alerts and may result in temporary account suspension for protection.

Domain Authentication

We enforce SPF, DKIM, and DMARC verification for all sending domains to prevent email spoofing and phishing. Domains cannot send email until DNS records are verified.

Session Management

Sessions are secured with signed tokens and configurable timeout policies. Multi-factor authentication is supported for sensitive operations.

Data Protection

Email Content: Your email messages and attachments are stored securely and are only accessible to authorized users within your organization. We do not read, scan, or use your email content for advertising purposes.

AI Processing: AI-powered features process your email content to generate summaries, categories, and draft replies. This processing is performed securely and is not shared with third parties or used to train external models.

Data Retention: Data is retained according to your account settings and our Privacy Policy. Deleted data is purged within 30 days of deletion, except where retention is legally required.

Backups: Data is backed up regularly with encrypted backups stored in geographically separated locations to ensure availability and disaster recovery.

Compliance and Standards

Our security practices align with industry frameworks and regulations including:

  • SOC 2: Our email delivery partner (Resend) maintains SOC 2 Type II compliance.
  • GDPR: We process personal data in accordance with the General Data Protection Regulation, including data subject rights and lawful processing bases.
  • CCPA: California consumers may exercise their rights under the California Consumer Privacy Act.
  • CAN-SPAM / CASL: Our platform includes tools to help you comply with anti-spam regulations, including unsubscribe handling and bounce management.

Incident Response

We maintain an incident response plan to identify, contain, and remediate security incidents. In the event of a confirmed data breach affecting your information, we will:

  • Investigate and contain the incident promptly;
  • Notify affected customers without undue delay, and in any case within 72 hours where legally required;
  • Provide details about the nature of the breach, data affected, and remediation steps taken;
  • Implement additional safeguards to prevent recurrence.

Responsible Disclosure

We welcome security researchers to report vulnerabilities responsibly. If you discover a security issue, please email us at help@nbxtd.com with a detailed description. We ask that you do not publicly disclose vulnerabilities until we have had a reasonable time to address them. We acknowledge all legitimate reports and work to remediate confirmed issues promptly.

Security Contact

For security-related questions, concerns, or reports, please contact us at help@nbxtd.com or through our Contact page. We are committed to maintaining the trust you place in us to protect your email infrastructure.

Ready to modernize
your email infrastructure?

Join the next generation of businesses running email on their own terms. Custom domains, AI assistance, and enterprise-grade delivery — all in one dashboard.