Information Security Policy
Technical and organisational controls implemented by CoffeeMail.
1. Commitment and Scope
Security is central to CoffeeMail. This document describes the technical and organisational controls implemented on the platform. The controls described here apply to production services, data at rest and in transit, and internal operations with access to customer data.
2. Infrastructure
The platform runs on Google Cloud, with managed services: Cloud Run for HTTP APIs, Cloud SQL (PostgreSQL) for persistence, Cloud Storage for attachments and backups, Cloud Logging for audit. Applications are deployed through automated pipelines with immutable images. Network configuration enforces private traffic between internal services and exposes only the necessary public endpoints.
3. Encryption
Data in transit: TLS 1.3 required on all public endpoints. Data at rest: AES-256 encryption managed by the database provider for production storage, and AES-256 encryption on attachment storage buckets. User passwords are stored using the bcrypt hash algorithm, the recommended algorithm for credentials.
4. Access Control
Access is controlled by RBAC with four roles: super_admin (Platform Owner), owner (organisation owner), admin (manages members, domains, API keys, webhooks and billing) and member (read-only access to metrics, logs, templates and suppressions). Internal routes (/v1/platform/*) require an HttpOnly session; product routes (/v1/product/*) require a Bearer API Key. Privileges are assigned on a least-privilege basis.
5. Authentication and MFA
Platform authentication is based on email and password, complemented by multi-factor authentication (MFA) via TOTP for accounts with elevated permissions. Sessions are kept in HttpOnly cookies with SameSite=Strict and can be invalidated by the user. Attempt limits and automatic lockouts mitigate credential attacks.
6. Logs and Auditing
Sensitive actions — login, role changes, data export, account deletion, API key changes, webhook changes — are recorded in an immutable audit log with a 12-month retention. Logs are reviewed by automated anomaly detection processes.
7. Rate Limiting and Stability
Public endpoints enforce rate limits per API key and per IP address, with X-RateLimit-* headers returned on every response. Limits protect the platform against abusive use and ensure stability for all customers. In stability incidents, status is communicated to the organisation owner.
8. Sub-processors
Customer personal data may be processed by sub-processors supporting the platform operation: Google Cloud (infrastructure), payment gateway (billing) and tax gateway (NFS-e issuance). The up-to-date list of sub-processors can be requested via the contato@coffeemail.com.br channel.
9. Retention and Purging
Sending logs and email events are retained for the period configured in the plan (between 7 and 90 days) and purged automatically after that period. Accounting records are kept for 5 years per Brazilian tax law. Personal data of subjects who request deletion is anonymised, preserving only accounting metadata required by law.
10. Vulnerability Management
We apply static analysis and mandatory review in continuous integration pipelines, automated dependency scanning for known vulnerabilities, and severity-based patching windows. Critical dependencies are updated on an emergency basis, outside the regular cycle, whenever necessary.
11. Contact
Questions about information security should be sent to contato@coffeemail.com.br. Formal communications and requests for additional information about controls can be made through this same channel.
12. Changes to this Policy
This Policy may be revised periodically. Material changes will be communicated with at least 30 days notice by email to the organisation owner. The current version is always available at /security and the last update date is shown at the top.