Skip to main content
Documentation

Security & Compliance

CoffeeMail is built for Brazilian enterprises with strict data and security requirements.

This page summarizes the published security controls. To access the full version of the DPA, Security Whitepaper, or penetration testing reports, open a ticket in Support with the subject "Security Pack".

LGPD Compliance

CoffeeMail is fully compliant with the LGPD. We support data export, deletion requests (DSAR), and detailed audit logs.

ISO 27001

Our infrastructure is certified under ISO/IEC 27001.

SOC 2 Type II

Annual third-party audits verify our security, availability, and confidentiality controls.

Encryption

TLS 1.3 in transit. AES-256 at rest. Per-tenant key separation.

Data Retention

Email content is purged 30 days after delivery (configurable). Metadata is retained for 90 days for analytics.

API Keys

  • Prefixos cm_live_ e cm_test_ isolados em quotas, métricas e dados.
  • Escopos granulares configuráveis.
  • Revogação imediata com status 401 Unauthorized.
  • Hash bcrypt em repouso.

Webhook signing

Assinatura com header X-CoffeeMail-Signature com HMAC SHA-256 e verificação timing-safe. Detalhes em Webhooks.