Concept
Security and compliance
How Emailit protects your account and data, from EU infrastructure, GDPR and retention controls to roles, 2FA, scoped API keys, signed webhooks and OAuth.
This page summarizes the security and privacy controls Emailit gives you, and the practices behind them. Use it for security reviews and vendor questionnaires, and to decide which controls to turn on for your team.
Where your data lives
Emailit’s infrastructure is operated in Prague, Czech Republic, in the European Union, and your sending data is kept in the EU. Emailit runs its own sending stack rather than reselling a third-party email service. Emailit is a service of FunFirst, Inc.
GDPR
For the personal data in the email you send and the contacts you store, you’re the controller and Emailit acts as your processor. Emailit gives you the tools to keep only what you need:
- Data retention. Message contents are kept for 7 days on Pay as you go and 30 days on Pro and Business by default. With the Data retention add-on you can choose 1 to 365 days for each data type. See Data retention.
- Deletion. Delete contacts, subscribers and suppressions from the dashboard or the API. For other deletion requests, email support@emailit.com.
- Consent records. Workspace verification asks how you collect subscribers, and campaigns include one-click unsubscribe headers.
A data processing agreement (DPA) is available on request. Contract (Custom) plans also include security reviews. Contact us to ask for either.
Account security
| Control | Details |
|---|---|
| Second factor on every sign-in | Password sign-ins always need a 6-digit code, emailed by default. |
| Authenticator apps | TOTP apps replace emailed codes. 8 single-use recovery codes. |
| Passkeys | WebAuthn sign-in with Touch ID, Face ID, Windows Hello or security keys. |
| Brute-force protection | 5 wrong codes lock sign-in for 15 minutes. 5 wrong invite codes lock code entry for 1 hour. |
| Short-lived codes | Sign-in and verification codes expire after 15 minutes. Password reset links expire after 60 minutes. |
| Password storage | Passwords are stored as salted hashes, never in plain text. |
| Bot protection | Sign-up is protected by Cloudflare Turnstile. |
See Sign-in and security and Two-factor authentication and passkeys.
Access control
- Workspaces isolate data. Nothing is shared between them, so you can separate brands, clients and environments. See Workspaces.
- Roles. Admins manage settings, members, API keys and billing. Members work with email and marketing but can’t change those. See Members and roles.
- Invitations must be accepted with the invited email address and expire after 7 days. Invite codes expire after 24 hours and only grant the Member role.
API keys
- Keys start with
secret_and are shown once, when you create or regenerate them. - Full access keys can use every endpoint. Sending only keys can only send, cancel, reschedule, retry and forward email.
- A sending key can be restricted to one sending domain. Sending from any other domain returns
403 Domain not authorized. - Regenerating a key stops the old secret immediately. Last used helps you find stale keys.
- Every request made with a key is recorded in Email APILogs.
Give apps and AI agents the narrowest key that works. See API keys.
Webhooks
Every webhook request is signed with HMAC-SHA256 using your endpoint’s secret. Verify the X-Emailit-Signature header against X-Emailit-Timestamp and the raw body, and reject old timestamps to block replays. Emailit only delivers to public http or https URLs, never to private IP addresses or localhost, and doesn’t follow redirects. See Verify webhook signatures.
Connected apps and MCP
Third-party apps and AI assistants connect through OAuth 2.1 with PKCE instead of copying API keys. You approve the connection on an Emailit consent page and choose which workspaces it can use: all of them or only the ones you select. Apps act with your role in each workspace, so a Member’s assistant can’t manage API keys or delete domains. Access tokens last 15 minutes, and refresh tokens rotate on every use. Review, narrow or revoke every connection under Connected apps. MCP tools carry annotations that mark read-only, destructive and outside-world actions, so assistants ask before acting. See OAuth apps and MCP workspaces and permissions.
Encryption
- In transit. The API, dashboard and webhooks use HTTPS. The SMTP relay offers TLS on every port: STARTTLS on 587, 25, 2525 and 2587, and implicit TLS on 465. TLS is offered but not required, so configure your client for port 587 with STARTTLS or port 465 with TLS. See SMTP settings.
- Stored secrets. Third-party credentials you give Emailit, such as a Cloudflare API token for one-click DNS, are encrypted with AES-256-GCM. Authenticator secrets and recovery codes are stored encrypted too.
- Outbound mail. Emailit signs your mail with DKIM for your domain and requires SPF and return-path records before a domain can send. See DNS records.
Abuse prevention
Protecting the shared reputation of Emailit’s IPs protects your deliverability too:
- New workspaces start in sandbox mode until the team approves production access.
- Sending health watches bounce rates hourly and can pause a domain or suspend a workspace.
- Messages that score 7 or higher in spam checks are held instead of sent.
- The Acceptable Use Policy bans cold email and purchased lists.
Report a security issue
Email support@emailit.com with “Security” in the subject. Include steps to reproduce and the affected account or workspace ID. Don’t include real customer data, and don’t test against accounts you don’t own.