Security & trust.
You hand a verification service real people's addresses, so how we handle them matters. Here is our security posture in plain terms - where your data lives, how we protect it, and the controls you keep over it.
Standards we build to

SOC 2
Our security program is built around the SOC 2 trust principles for security, availability, and confidentiality.

GDPR
We build to the GDPR - lawful processing, data-subject rights, and a clear record of where your data is stored.

HIPAA
Our practices are designed to support HIPAA obligations for teams that handle protected health information.
Need our latest reports, a Data Processing Agreement (DPA), or a Business Associate Agreement (BAA)? Get in touch and we'll share what applies to your use case.
How we protect your data
Where your data is stored
Depending on your workspace, the data you send us is stored and processed in the EU or the United States. Either way it stays with us and our vetted infrastructure providers, under the same controls. Get in touch if you need your data kept in a specific region.
Encryption & access controls
We apply technical and organizational safeguards (encryption, least-privilege access controls, and regular security assessments) to protect your account and the lists you verify.
Scoped API keys
Verify over the API with scoped, revocable keys so each integration gets only the access it needs, and you can rotate or revoke a key without touching the rest of your setup.
Your data, your control
Verification jobs and results live in your workspace and you can delete them at any time. We never sell, rent, or share the email lists you submit - and we don't use them to train models or enrich anyone else's results.
Data retention
We keep data only as long as there's a reason to. The full schedule is in the privacy policy; in short:
- Verification jobs and results: kept in your workspace until you delete them or close your account.
- Account data: retained while your account is open, then removed 30 days after closure.
- Usage logs: kept 90 days for security and analytics.
- Billing records: retained to meet tax and accounting law.
Questions about security or compliance?
We're happy to walk through our practices, sign a DPA, or answer a security questionnaire - just reach out.