Security & Compliance
WarmySender takes security seriously. Here is an overview of our security practices:
Data Encryption:
- All data in transit is encrypted using TLS 1.2+ (HTTPS). Every connection between your browser and our servers is encrypted.
- Your WarmySender account has no password at all — you sign in with a single-use 6-digit code we email you, so there is no account password to steal, leak, or reuse anywhere else.
- API keys are hashed with industry-standard algorithms; we never store them in readable form.
- Database connections use SSL encryption.
Authentication & Access:
- Passwordless sign-in with single-use emailed codes, and secure HTTP-only session cookies.
- Two-factor authentication support for LinkedIn account connections.
- API keys support granular scopes (read/write per resource type) and optional expiration dates.
- Role-based access control: Owner, Admin, User, Readonly roles with enforced permission boundaries.
- Failed login attempts are rate-limited to prevent brute force attacks.
Infrastructure:
- Application and database hosted on secure cloud infrastructure, with automatic backups and point-in-time recovery.
- Internal service connections are encrypted.
- Regular security updates and dependency patching.
Email Security:
- SMTP connections support TLS/SSL encryption.
- SSRF protection: the system validates that SMTP/IMAP hostnames do not resolve to private or internal IP addresses.
- Port validation: only standard email ports are allowed.
- Connection testing before accepting mailbox credentials.
Compliance:
- CAN-SPAM: Every campaign email includes an unsubscribe link and respects opt-out requests immediately.
- GDPR: Data processing with user consent, right to erasure via account deletion, suppression list management.
- LinkedIn: All automation follows LinkedIn's Terms of Service with conservative rate limits, ramp-up periods, and circuit breakers.
- Unsubscribe handling follows RFC 2369 and RFC 8058 standards.
Data Retention:
- You control your data — export or delete at any time.
- Campaign data and analytics are retained while your account is active.
- Upon account deletion your access ends immediately and your data is deleted within 30 days, except for the small amount we are legally required to keep (such as billing records). See /documentation/cancel-or-delete-your-account.
Security Page:
For our full security policy, visit warmysender.com/security.
Privacy Policy: warmysender.com/privacy.
For security inquiries, contact us at [email protected].