Security

Guarded like it's ours.

Most of what protects you on Transmit is the same thing that protects the inbox from bad senders. This page lists what we do, in plain words, and only the parts we can stand behind.

Last updated September 2026

01Reputation

Your reputation is isolated.

Every account sends from its own verified domain, with its own DKIM keys, and is tracked as its own tenant at the sending provider. No shared sending domains, no pooled reputation. A problem on another account cannot touch your deliverability.

Before the first send.

Card on file and domain ownership are verified before the first message leaves.

Screened at the door.

Every accepted message is screened before a provider sees it. Held messages are shown to you with the reason.

Lists that go bad pause.

Bounce and complaint rates are enforced on every account. Sending is paused automatically when a list goes bad.

Authenticated end to end.

SPF, DKIM, and DMARC are set up through the records you add at verification, so mail from your domain is authenticated end to end.

02Keys

Shown once. Stored as a hash.

A copy of our database does not yield a working key. Revocation takes effect on the next request.

API keys

Shown once, at creation. We store only a keyed hash. Keys carry scopes and can be revoked instantly from the dashboard.

Rate limits

Requests are rate limited per key and per account.

Passwords

Hashed with a modern, salted algorithm and never logged.

Payments

Payment details never touch our servers. Stripe collects and stores them.

03Data

We do not read your messages.

Except to resolve a support request you have opened. We never use them to train models. Content lives only long enough to deliver and to show you the receipt.

In motion

Every connection to the API and the dashboard is over HTTPS. Plain HTTP is refused.

At rest

Databases, object storage, and backups are encrypted at rest by the providers that host them.

04Retention

Thirty days, then gone.

You can request deletion of your data at any time from the dashboard or by writing to support@transmit.dev.

Message bodies and attachments
30 days, then permanently deleted
Delivery metadata and logs
365 days, for receipts and troubleshooting
Account data after closure
30 days, then deleted
Payment records
7 years, as tax law requires

05Audit

No report to show you yet.

WeWill3C, LLC, the company behind Transmit, is in an active SOC 2 Type II audit. A Type II is observed over a period rather than granted on a date, so there is no report to show you yet. When the auditors issue one, we will make it available under NDA.

Continuous monitoring

Our controls are monitored continuously in Vanta, not assembled the week before an assessment.

The programme

The security programme behind them is run with Workstreet.

Until then

Until the report exists, we are not SOC 2 certified and will not say we are. This page is the accurate description of what we do.

06Disclosure

Write to us first.

If you find a security issue, write to support@transmit.dev with "SECURITY" in the subject line. We read those first.

Good-faith research

Good-faith research is welcome. We will not pursue legal action against responsible disclosure.

A reasonable window

Give us a reasonable window to fix the issue before publishing it.

Credit

We'll credit you in our acknowledgments if you'd like.

Email that arrives.

The checks are the product. Build in sandbox. Subscribe when you're ready for live email.

Start free in sandbox