Last updated: September 10, 2026
MailBond™ is built for organizations that handle sensitive information — financial institutions, legal teams, and regulated enterprises. This page summarizes how we protect your data. Detailed security documentation, including our architecture overview, subprocessor data-flow breakdown, and Data Processing Agreement, is available to prospects and customers under NDA — contact admin@mailbond.us.
MailBond is designed to analyze email content without retaining the request content. Each scan is ephemeral: the request is validated, analyzed, returned as a verdict, and then destroyed. When a user scans an email:
Full retention timelines are covered in our Privacy Policy. Authorized customer administrators can export scan history before the 90-day retention window expires, and scan history can be deleted on request at any time.
MailBond is hosted on Microsoft Azure in the United States. Public application endpoints are protected by Azure Front Door Web Application Firewall, and origin services reject traffic that does not arrive through the authorized Front Door path. Attachment parsing and browser rendering run in a separate non-root Azure Container App with Chromium process isolation enabled, VNet/NSG isolation, API-restricted ingress, SSRF controls, and monitored network boundaries. Key Vault and backup storage have public access disabled and use private endpoints. Applications access secrets through managed-identity Key Vault references. Registry backups authenticate with managed identity rather than account keys or connection strings, and backup storage uses customer-managed-key encryption. Azure maintains independent compliance attestations for covered Azure infrastructure and platform services, including SOC 2 Type II and ISO 27001-family certifications.
MailBond SOC 2. MailBond is currently undergoing a SOC 2 audit. Azure's separate compliance attestations continue to support the inherited infrastructure and platform controls used by MailBond.
MailBond's current analysis pipeline uses multiple independent signal categories for links, sender authenticity, social-engineering patterns, supported attachments, image-based lures, QR-based lures, and brand impersonation. Results are presented to users with severity-colored risk bubbles: red for dangerous indicators, orange for suspicious medium-risk indicators, and gray for low-context observations.
We use the following third-party services to operate MailBond. Each is bound by its own security and privacy commitments, and we only share the minimum data necessary for each vendor's function.
| Subprocessor | Purpose | Location |
|---|---|---|
| Microsoft Azure | Cloud infrastructure (compute, storage, networking) and transactional email delivery via Microsoft Graph | United States |
| Microsoft Entra ID / Microsoft identity services | Required Office SSO for Outlook browser requests and Microsoft sign-in for customer dashboard access. MailBond does not maintain separate user or dashboard passwords. | Microsoft cloud regions |
| Google Web Risk | URL reputation lookup for extracted, OCR-discovered, and QR-decoded URLs. No email body, attachment bytes, screenshots, or customer identifiers are sent. | United States |
| PhishTank | Crowdsourced phishing URL reputation lookup for extracted, OCR-discovered, and QR-decoded URLs. No email body, attachment bytes, screenshots, or customer identifiers are sent. | United States |
| IPWho | On-demand approximate geolocation and network attribution for a validated public sender mail-relay IP when an authorized tenant administrator views scan history. No email content or customer identifier is sent. | Global service |
| Stripe | Payment processing and subscription billing | United States |
A detailed breakdown of exactly which data fields are shared with each subprocessor is available in our security documentation package on request.
A Data Processing Agreement (DPA) covering controller/processor responsibilities, breach notification, subprocessor changes, data subject rights, and international data transfers is available for qualified customers. Request a copy by emailing admin@mailbond.us.
We maintain an internal incident response procedure covering detection, containment, customer notification, and post-incident review. In the event of a security incident that affects customer data, we will notify affected customers without undue delay and within the timeframe required by applicable law and contract.
We welcome reports from security researchers. If you believe you have found a vulnerability in MailBond, please email security@mailbond.us with details. We commit to:
For prospects and customers evaluating MailBond for regulated environments, we provide a detailed security package under NDA that includes:
Contact admin@mailbond.us to begin the NDA and documentation exchange.
MailBond LLC
100 W High St, PO Box 1153
Moorpark, CA 93020
General security inquiries: admin@mailbond.us
Privacy / DPA requests: privacy@mailbond.us
Vulnerability disclosure: security@mailbond.us