MailBond MailBond™
Home Features Pricing Request Demo

Security & Trust

Last updated: September 10, 2026

MailBond™ is built for organizations that handle sensitive information — financial institutions, legal teams, and regulated enterprises. This page summarizes how we protect your data. Detailed security documentation, including our architecture overview, subprocessor data-flow breakdown, and Data Processing Agreement, is available to prospects and customers under NDA — contact admin@mailbond.us.

1. Data We Process vs. Data We Store

MailBond is designed to analyze email content without retaining the request content. Each scan is ephemeral: the request is validated, analyzed, returned as a verdict, and then destroyed. When a user scans an email:

  • Request content — email body, attachments, screenshots, OCR text, and decoded QR/barcode payloads — is processed for the scan and is not written to persistent storage.
  • Minimized scan metadata — timestamp, tier, risk score, primary risk reason, attachment count, sender and recipient domains, and available public sender mail-relay IP — is retained for up to 90 days so dashboard, audit-log, scan-history, and export features are available to your security team.
  • Optional address detail — an authorized tenant administrator may explicitly retain encrypted full sender and recipient addresses for 7 or 30 days, extend unexpired records manually by 30 days, select one automatic extension, or select continuous retention capped at one year with annual reconfirmation. Expired addresses are permanently scrubbed, and disabling the setting immediately removes retained full addresses.
  • Message-specific details — subjects, URLs, attachment names and content, headers, screenshots, OCR text, and decoded QR/barcode payloads — are never persisted in production scan logs.

Full retention timelines are covered in our Privacy Policy. Authorized customer administrators can export scan history before the 90-day retention window expires, and scan history can be deleted on request at any time.

2. Encryption

  • In transit: all traffic between the MailBond Outlook add-in, our API, and our infrastructure is encrypted using TLS 1.2 or higher.
  • At rest: persisted data is encrypted on Azure storage. Registry backups use customer-managed-key encryption.
  • Browser authentication: Outlook requests use fresh Microsoft Office SSO bearer tokens. The API validates each token's signature, audience, issuer, scope, tenant, object ID, expiry, and customer mapping.
  • Machine authentication: registry API keys are limited to explicitly authorized machine integrations. Only SHA-256 hashes are stored; browser requests and the add-in proxy do not contain or inject these keys.

3. Access Controls

  • Outlook permission scope: the MailBond add-in requests ReadItem permission only — the minimum needed to analyze the currently open email. MailBond cannot read other messages, modify mail, or send on your behalf.
  • Customer authentication: administrators sign in to the customer dashboard using Microsoft Single Sign-On. No separate MailBond passwords to manage.
  • Scan integrity: every selected message proceeds through analysis regardless of sender; MailBond does not provide sender-based scan bypasses.
  • Internal access: production systems and customer data are accessible only to a small number of authorized engineers, following least-privilege principles and audited access.

4. Infrastructure

MailBond is hosted on Microsoft Azure in the United States. Public application endpoints are protected by Azure Front Door Web Application Firewall, and origin services reject traffic that does not arrive through the authorized Front Door path. Attachment parsing and browser rendering run in a separate non-root Azure Container App with Chromium process isolation enabled, VNet/NSG isolation, API-restricted ingress, SSRF controls, and monitored network boundaries. Key Vault and backup storage have public access disabled and use private endpoints. Applications access secrets through managed-identity Key Vault references. Registry backups authenticate with managed identity rather than account keys or connection strings, and backup storage uses customer-managed-key encryption. Azure maintains independent compliance attestations for covered Azure infrastructure and platform services, including SOC 2 Type II and ISO 27001-family certifications.

5. Independent Assurance

MailBond SOC 2. MailBond is currently undergoing a SOC 2 audit. Azure's separate compliance attestations continue to support the inherited infrastructure and platform controls used by MailBond.

6. Current Detection Safeguards

MailBond's current analysis pipeline uses multiple independent signal categories for links, sender authenticity, social-engineering patterns, supported attachments, image-based lures, QR-based lures, and brand impersonation. Results are presented to users with severity-colored risk bubbles: red for dangerous indicators, orange for suspicious medium-risk indicators, and gray for low-context observations.

7. Subprocessors

We use the following third-party services to operate MailBond. Each is bound by its own security and privacy commitments, and we only share the minimum data necessary for each vendor's function.

SubprocessorPurposeLocation
Microsoft AzureCloud infrastructure (compute, storage, networking) and transactional email delivery via Microsoft GraphUnited States
Microsoft Entra ID / Microsoft identity servicesRequired Office SSO for Outlook browser requests and Microsoft sign-in for customer dashboard access. MailBond does not maintain separate user or dashboard passwords.Microsoft cloud regions
Google Web RiskURL reputation lookup for extracted, OCR-discovered, and QR-decoded URLs. No email body, attachment bytes, screenshots, or customer identifiers are sent.United States
PhishTankCrowdsourced phishing URL reputation lookup for extracted, OCR-discovered, and QR-decoded URLs. No email body, attachment bytes, screenshots, or customer identifiers are sent.United States
IPWhoOn-demand approximate geolocation and network attribution for a validated public sender mail-relay IP when an authorized tenant administrator views scan history. No email content or customer identifier is sent.Global service
StripePayment processing and subscription billingUnited States

A detailed breakdown of exactly which data fields are shared with each subprocessor is available in our security documentation package on request.

8. Data Processing Agreement

A Data Processing Agreement (DPA) covering controller/processor responsibilities, breach notification, subprocessor changes, data subject rights, and international data transfers is available for qualified customers. Request a copy by emailing admin@mailbond.us.

9. Incident Response

We maintain an internal incident response procedure covering detection, containment, customer notification, and post-incident review. In the event of a security incident that affects customer data, we will notify affected customers without undue delay and within the timeframe required by applicable law and contract.

10. Responsible Disclosure

We welcome reports from security researchers. If you believe you have found a vulnerability in MailBond, please email security@mailbond.us with details. We commit to:

  • Acknowledging your report within 3 business days.
  • Investigating and responding with a remediation plan within 30 days.
  • Not pursuing legal action against researchers who act in good faith, do not disrupt our service, and do not access customer data beyond what is necessary to demonstrate the issue.

11. Requesting the Full Security Package

For prospects and customers evaluating MailBond for regulated environments, we provide a detailed security package under NDA that includes:

  • Architecture overview with data-flow diagrams
  • Subprocessor data-sharing breakdown (field-level)
  • Ephemeral request processing and data-minimization summary
  • Data Processing Agreement
  • MailBond is currently undergoing a SOC 2 audit
  • Completed CAIQ / SIG Lite questionnaire (as available)
  • Vulnerability management and SDLC summary

Contact admin@mailbond.us to begin the NDA and documentation exchange.

12. Contact

MailBond LLC
100 W High St, PO Box 1153
Moorpark, CA 93020
General security inquiries: admin@mailbond.us
Privacy / DPA requests: privacy@mailbond.us
Vulnerability disclosure: security@mailbond.us

© 2026 MailBond LLC. MailBond™ is a trademark of MailBond LLC. USPTO Serial No. 99836871. All rights reserved. · EULA / Terms · Privacy Policy · Security