Trust & security

The safest copy of an email is no copy.

You're trusting us with your customers' mail. Here is exactly what happens to it, and the controls around everything else.

  1. 0 msArrivesOnly for addresses you listed. Anything else is refused before the message is even sent.
  2. in memoryChecked & parsedAuthentication, scanning and extraction happen in memory and are never written to disk.
  3. signedDeliveredTo the places you chose, over HTTPS, with a signature you can verify.
  4. thenForgottenThe content is gone. Only delivery metadata stays, for your delivery log, for 90 days at most.

Controls, not promises.

Secrets encrypted

Webhook secrets, signing keys and destination URLs are encrypted with AES-256-GCM. API keys are stored only as hashes.

Signed webhooks

Standard Webhooks signatures, with secret rotation and a grace period so you never drop a request.

Published IP addresses

Firewall your endpoint to the addresses we send from: 77.72.7.69, 2a03:2800:500::52f. Also at /v1/meta.

No private networks

Deliveries can't be pointed at internal addresses, and that's checked again at connect time to stop DNS tricks.

2FA, roles & audit

Require two-factor login for your whole team, give least-privilege roles, and see every change in the audit log.

Scanning stays in-house

Spam and virus checks run on our own servers. No email is sent to a third party for processing.

Paperwork, ready

Built for UK GDPR.

A Data Processing Agreement is part of our Terms, with no forms to sign. GhostParse is run by WILDYE LIMITED.

Data region
United Kingdom
Hosting provider
WILDYE LIMITED
Sub-processors
Listed in the DPA, with 30 days' notice of changes
Email content kept
None
Delivery metadata kept
Up to 90 days
Contact
hello@wildye.com

Questions from your security team?

Send them over and we'll answer in writing.

Contact us