Documentation
Security & Compliance
CoffeeMail is built for Brazilian enterprises with strict data and security requirements.
This page summarizes the published security controls. To access the full version of the DPA, Security Whitepaper, or penetration testing reports, open a ticket in Support with the subject "Security Pack".
LGPD Compliance
CoffeeMail is fully compliant with the LGPD. We support data export, deletion requests (DSAR), and detailed audit logs.
ISO 27001
Our infrastructure is certified under ISO/IEC 27001.
SOC 2 Type II
Annual third-party audits verify our security, availability, and confidentiality controls.
Encryption
TLS 1.3 in transit. AES-256 at rest. Per-tenant key separation.
Data Retention
Email content is purged 30 days after delivery (configurable). Metadata is retained for 90 days for analytics.
API Keys
- Prefixos
cm_live_ecm_test_isolados em quotas, métricas e dados. - Escopos granulares configuráveis.
- Revogação imediata com status 401 Unauthorized.
- Hash bcrypt em repouso.
Webhook signing
Assinatura com header X-CoffeeMail-Signature com HMAC SHA-256 e verificação timing-safe. Detalhes em Webhooks.