Security
Your mail is yours alone
AirSend hosts email for many organisations on one platform. Here is how we keep each one's mail apart, visible only to the right people, and safe to open.
Isolation
Organisations kept apart
Keeping one customer's mail from another's doesn't depend on any one check being right.
Kept apart in the database itself
Customer data is protected by row-level security in PostgreSQL, so a request can reach only its own organisation's rows, even if a query in the application forgets to ask for them.
Least privilege for every service
Each of our services connects with its own database role, granted only what that service needs. None of them can bypass row-level security, and there is no shared account to fall back on.
Separated in three ways
Code for one part of the platform is not even loaded by another. Reading another organisation's mail would take all three layers failing at once.
Access
Every look at your mail is approved and recorded
Administrators and our own staff alike need permission to see a mailbox that isn't theirs, and it's written down when they do.
Mailbox access needs an Owner's approval
An administrator who needs to see someone's mailbox has to ask. An Owner decides, nobody can approve their own request, and access ends when the approved window does.
Our staff can't browse your mail
AirSend staff reach customer mail only through an approved, time-limited elevation, and every use of it is recorded separately.
An audit log that can't be rewritten
Each entry carries a hash of the one before it, and the log can be added to but never edited. Change or remove an entry and the chain breaks where you did it. Our own staff log is also anchored off-site every day.
Safe to open, hard to fake
Protection for the messages themselves, from the moment they arrive to the moment you read them.
Attachments scanned before they're served
Files you receive and files you attach are scanned for viruses. A file waits until the scanner has answered, and an infected one is withheld or refused, never passed on with a warning.
Messages shown in a sandbox
A message's HTML is cleaned and then shown in an isolated frame, so a sender's markup can't reach the app around it. Remote images wait until you allow them, so tracking pixels don't fire when you open a message.
Nobody sends as your domain but you
Mail is sent from a domain only after the workspace has proved it owns it, with DKIM, SPF and DMARC records it adds itself.
Two-factor sign-in and device control
Protect accounts with an authenticator app. See every device that's signed in, and sign out any of them.
Give your team email on your own domain
Set up your workspace in a few minutes. Your first 14 days are free, and no card is needed to begin.