KapoMail

Security & Trust

Version 1.0 Effective 2026-08-19 Updated 2026-08-21

1. Where your data lives

KapoMail is built and hosted in the United Kingdom. Message data, account data and delivery metadata are stored on Amazon Web Services in the eu-west-2 (London) region. We do not route or store message content outside the UK.

Cloudflare provides DNS resolution and network-layer protection (DDoS mitigation, TLS termination at the edge) in front of the platform; it sees connection metadata such as IP addresses and request headers, not message content.

2. Encryption

3. Isolation

Every sending credential is bound to the specific domains it is permitted to send from. A credential compromised on one site or one client project cannot be used to send as another — including within your own account, if you run multiple projects or, as an agency, multiple clients. When our abuse detection identifies anomalous sending from a credential, we suspend that credential alone rather than the whole account.

4. Access control

Access to production systems and customer data is limited to the staff who need it to operate or support the service, is individually attributed rather than shared, and is logged. We do not have a large support organisation with broad standing access — a small team is, in this respect, a narrower attack surface than a large one.

5. Sub-processors

We use the following sub-processors to provide the service. We will notify customers at least 14 days before adding a new one that processes message data, consistent with our Data Processing Agreement.

Sub-processor Purpose Data it can access Location
Amazon Web Services (AWS) Hosting and email delivery infrastructure Message content, recipient addresses, delivery metadata eu-west-2 (London), UK
Cloudflare DNS and CDN / DDoS protection Connection metadata only Global edge network
Stripe Payment processing Billing data (not message or recipient data) UK / EU

6. Retention

We keep different categories of data for different lengths of time, deliberately — a shorter default is safer for you and for us. Full detail is in our Privacy Notice and DPA; in summary:

Data Default retention
Message bodies and attachments 30 days
Delivery events (bounces, complaints, opens) 90 days
Audit and security logs 7 years
Suppression list entries Kept while your account is active, minimised to address and reason

7. Reporting a vulnerability

We welcome reports from security researchers, and we would rather hear about a problem from you than find it ourselves after it has been exploited.

How to report: email security@kapomail.com with a description of the issue, the steps to reproduce it, and its potential impact. Encrypt sensitive detail if you are able to; otherwise a clear written description is fine. We aim to acknowledge a report within 2 business days and to give you a substantive update within 10 business days.

Safe harbour. If you make a good-faith effort to:

then we will not pursue legal action against you for that research, and we will not report it to law enforcement. This safe harbour applies to good-faith security research; it does not extend to accessing, exfiltrating or publishing customer data, to social engineering our staff or customers, or to physical intrusion.

Scope. In scope: the KapoMail dashboard, sending API, SMTP relay, and public marketing site. Out of scope: our sub-processors' own infrastructure (report those to AWS, Cloudflare or Stripe directly), and denial-of-service testing against production.

Recognition. We do not currently run a paid bug bounty. Where you would like credit, we are glad to acknowledge confirmed reports publicly, with your permission, once a fix has shipped.

8. Incident response

If we identify or are notified of a security incident affecting customer data, we investigate immediately, contain it as our first priority (which may mean suspending an affected credential or account before we have the full picture), and notify affected customers without undue delay — within 72 hours where the incident is a personal data breach, consistent with our DPA.

9. Questions

For anything not covered here — an enterprise security questionnaire, a request for our sub-processor list in another format, or a specific control you need documented — write to security@kapomail.com.


Contact: HRMFIRM LTD, Flat 3 Carradale House, 88 St. Leonards Road, London, England, E14 0SN · security@kapomail.com