Security

Last updated: February 15, 2026

1. Security Governance

Security is embedded in our development lifecycle, not treated as an afterthought. We maintain organizational practices that ensure security is a continuous priority across every level of our platform.

2. Risk Management

We take a structured approach to identifying, assessing, and mitigating risk across our infrastructure, application layer, and third-party dependencies.

3. Vulnerability Management

We proactively identify, track, and remediate security vulnerabilities across our codebase and dependencies.

4. Compliance Alignment

Our security practices are informed by industry-standard frameworks including SOC 2 Trust Service Criteria and HIPAA Security Rule requirements.

We are committed to expanding our formal compliance program as we grow. For specific compliance questions or to request our security documentation, contact hello@warmysender.com.

5. Infrastructure Security

WarmySender is hosted on enterprise-grade infrastructure with HTTPS enforced on all connections. Our PostgreSQL database is managed by Neon, which provides automated daily backups, point-in-time recovery, and encryption at rest. All data in transit between services is encrypted using TLS 1.2 or higher.

6. Data Encryption

We employ strong encryption standards to protect your data at every layer:

7. Authentication & Access Control

WarmySender implements multiple layers of authentication and authorization:

8. Payment Security

All payment processing is handled by Stripe, a PCI DSS Level 1 certified payment processor. WarmySender never stores, processes, or has access to your full credit card numbers. Payment forms are rendered directly by Stripe's secure elements, and all billing operations go through Stripe's API with webhook signature verification (HMAC-SHA256) to prevent tampering.

9. API Security

The WarmySender Public API (v1) is protected with industry-standard security measures:

10. Email Account Security

Your connected email accounts are handled with care:

11. Data Retention & Deletion

We follow data minimization principles and provide clear retention policies:

12. Security Headers

WarmySender enforces security headers on all HTTP responses via Helmet.js:

13. Monitoring & Incident Response

We actively monitor our systems to detect and respond to issues quickly:

14. Responsible Disclosure

We take security vulnerabilities seriously. If you discover a security issue, please report it responsibly:

We appreciate the security research community's efforts in helping keep WarmySender and our users safe.