Version 1
Security
OutreachEU is built on privacy by design and by default. These are our main technical and organisational measures.
Data isolation per workspace
Every table holding customer data is protected by database Row Level Security: users can only read and change data of workspaces they belong to. Management actions (members, mailboxes, settings) are restricted to owners and admins.
Encrypted mailbox credentials
App passwords and OAuth tokens are encrypted at rest with AES-GCM using a server-side key. They are stored in a table that the browser cannot access and are never returned to the interface. Microsoft 365 uses OAuth, without passwords.
Mailbox reading limited to headers
To detect replies and bounces we first download only a few headers (Message-ID, In-Reply-To, References, Subject and a few more). Content is downloaded only for replies to platform threads or delivery-failure reports. The rest of the mailbox is never read. Received HTML is sanitised and all remote images are removed.
Anonymous, aggregate pixel
We do not track individual opens. One identical pixel for all recipients of a step, no IP address read, no cookies, only total counters in a separate schema, statistics shown only above 50 recipients and 48 hours after sending ends. No link redirects and no per-recipient parameters.
Limited retention
Contacts not emailed for N months (default 24) and inbox messages older than N months (default 12) are deleted automatically every day. The suppression list stores only an HMAC-SHA256 of the address, never the plain email.
Activity log
Administrative actions are recorded in an append-only audit log that users cannot edit or delete. It never contains per-recipient events.
Other measures
- Encrypted connections (HTTPS/TLS) everywhere.
- Server-side validation of all input.
- No personal data in application logs or error messages.
- No third-party analytics or tracking libraries; self-hosted fonts.
- Automatic abuse controls (bounces, unsubscribes, daily caps, gradual warm-up).
To report a vulnerability: security@[DOMAIN].