Guarded like it's ours.
Most of what protects you on Transmit is the same thing that protects the inbox from bad senders. This page lists what we do, in plain words, and only the parts we can stand behind.
01Reputation
Your reputation is isolated.
Every account sends from its own verified domain, with its own DKIM keys, and is tracked as its own tenant at the sending provider. No shared sending domains, no pooled reputation. A problem on another account cannot touch your deliverability.
Card on file and domain ownership are verified before the first message leaves.
Every accepted message is screened before a provider sees it. Held messages are shown to you with the reason.
Bounce and complaint rates are enforced on every account. Sending is paused automatically when a list goes bad.
SPF, DKIM, and DMARC are set up through the records you add at verification, so mail from your domain is authenticated end to end.
02Keys
Shown once. Stored as a hash.
A copy of our database does not yield a working key. Revocation takes effect on the next request.
Shown once, at creation. We store only a keyed hash. Keys carry scopes and can be revoked instantly from the dashboard.
Requests are rate limited per key and per account.
Hashed with a modern, salted algorithm and never logged.
Payment details never touch our servers. Stripe collects and stores them.
03Data
We do not read your messages.
Except to resolve a support request you have opened. We never use them to train models. Content lives only long enough to deliver and to show you the receipt.
Every connection to the API and the dashboard is over HTTPS. Plain HTTP is refused.
Databases, object storage, and backups are encrypted at rest by the providers that host them.
04Retention
Thirty days, then gone.
You can request deletion of your data at any time from the dashboard or by writing to support@transmit.dev.
- Message bodies and attachments
- 30 days, then permanently deleted
- Delivery metadata and logs
- 365 days, for receipts and troubleshooting
- Account data after closure
- 30 days, then deleted
- Payment records
- 7 years, as tax law requires
05Audit
No report to show you yet.
WeWill3C, LLC, the company behind Transmit, is in an active SOC 2 Type II audit. A Type II is observed over a period rather than granted on a date, so there is no report to show you yet. When the auditors issue one, we will make it available under NDA.
Our controls are monitored continuously in Vanta, not assembled the week before an assessment.
The security programme behind them is run with Workstreet.
Until the report exists, we are not SOC 2 certified and will not say we are. This page is the accurate description of what we do.
06Disclosure
Write to us first.
If you find a security issue, write to support@transmit.dev with "SECURITY" in the subject line. We read those first.
Good-faith research is welcome. We will not pursue legal action against responsible disclosure.
Give us a reasonable window to fix the issue before publishing it.
We'll credit you in our acknowledgments if you'd like.
Email that arrives.
The checks are the product. Build in sandbox. Subscribe when you're ready for live email.