Security

Keeping your email and your account safe.

Here’s how we look after your email, your account and the people you write to, in plain words.

Access

Only the access each thing needs.

Teammates get workspace roles. Integrations get API keys scoped to just what they do. AI agents work in one workspace, with the permissions you approved.

The key list shows only a short prefix for each key, along with what it can do, when it was last used and when it expires.

  • Revoke a key or an agent’s access anytime
  • Every agent action is attributed to its connection
The API keys settings page lists five keys, each showing only a short prefix, its permissions, last used date, expiry and created date, with a Revoke link for each.

In transit

Encrypted on the way.

Your email and your API requests travel over encrypted connections.

  • HTTPS for the APIEvery API request travels over HTTPS.
  • Into getreadConnections into getread’s mail servers use TLS 1.2 or newer, with authenticated STARTTLS.
  • To your recipientsWe use TLS, and verify the certificate, whenever the receiving server offers it.
  • No quiet downgradesIf TLS fails with a receiving server, we don’t silently retry that server without encryption.

Signing in

Sign in your way, safely.

  • PasskeysSign in with a passkey on your device.
  • Password, Google or GitHubChoose whichever sign-in suits you.
  • Multi-factor authenticationAdd a second step to keep your account yours.
  • Careful with passwordsPasswords are hashed with argon2id, never stored as you typed them.

Your recipients

Kind to the people you write to.

  • One-click unsubscribeEvery campaign supports one-click unsubscribe (RFC 8058).
  • Suppressed everywhereBounces, complaints and unsubscribes are suppressed across every source, including your AI agent.
  • Your own domainGuided DKIM, SPF and DMARC records, so inboxes know your email really comes from you.
  • Previews that don’t trackLooking at a message in Mailroom never loads tracking pixels or follows links.

Questions about security

Is my email encrypted in transit?
Yes. The API is served over HTTPS, and connections into our mail servers use TLS 1.2 or newer, with authenticated STARTTLS. When we deliver to your recipients, we use TLS with certificate verification whenever their server offers it.
What happens if TLS fails with a recipient's server?
We don’t silently retry that server without encryption.
How can I sign in?
With a password, a passkey, Google or GitHub. You can add multi-factor authentication too.
How are passwords stored?
They’re hashed with argon2id. We never store the password itself.
Can I limit what an API key or an AI agent can do?
Yes. API keys are scoped to the permissions you choose, and an AI agent works in one workspace with only the permissions you approved. You can revoke either one anytime.
How do I report a security concern?
Please talk to us. A real person will read it.

Have a security question?

Tell us what you need to know, and a real person will help.

[TRIAL TERMS]