Security & Compliance

Built on a foundation of
Trust & Security

CASA Tier 2 Certified SOC 2–Aligned Controls GDPR Compliance

Predimail protects your data with layered controls across encryption, identity & access management, secure development, monitoring, and incident response. Below is a transparent overview of our practices.

CASA Tier 2 Cloud Security Assessment
SOC 2 Aligned Controls & Monitoring
GDPR Compliant DPA available on request
AES-256 Encryption at rest

Last updated: 09/11/2025

Data Protection

Encryption in Transit & at Rest

Every byte of your data is protected whether it's moving across the network or stored on our servers.

Transit Encryption

  • TLS 1.2+ enforced for all network connections
  • HTTP Strict Transport Security (HSTS) enabled
  • Certificate pinning for critical service calls

At-Rest Encryption

  • AES-256 encryption for all stored data
  • Database-level and disk-level encryption
  • Encrypted backups with limited retention

Key Management

  • Encryption keys held with restricted access controls
  • Automated key rotation policies enforced
  • Key access fully audited and logged
Identity & Access

Access & Identity Management

Strict access controls ensure only the right people reach the right resources, with full auditability.

Least-Privilege RBAC

  • Role-based access control (RBAC) across all systems
  • Principle of least-privilege enforced by default
  • Scoped permissions reviewed quarterly

Multi-Factor Authentication

  • MFA enforced for all privileged operations
  • Single Sign-On (SSO) via enterprise identity providers
  • Session expiry and forced re-authentication policies

Environment Segregation

  • Fully segregated production, staging, and development environments
  • Admin actions audited with immutable logs
  • Network-level isolation between service tiers
Certifications

Compliance & Certifications

We hold independently verified certifications and maintain ongoing compliance with global regulations.

Your compliance requirements, covered

Predimail undergoes independent third-party assessments and maintains documented compliance evidence for all major security frameworks.

CASA Tier 2 Certified SOC 2–Aligned Controls GDPR Article 28 DPA Security by Design

CASA Tier 2 Certified

  • Independently assessed Cloud Application Security
  • Annual re-assessment and continuous control monitoring
  • Documentation available for enterprise customers

GDPR Compliance

  • Full GDPR compliance for EU/EEA personal data
  • Data Processing Addendum (DPA) available on request
  • User rights: access, erasure, portability, and restriction

SOC 2–Aligned Controls

  • Controls aligned to SOC 2 Trust Services Criteria
  • Covers: security, availability, and confidentiality
  • Continuous control validation and evidence collection
API Integrations

Google & Microsoft API Usage

Predimail integrates with Google and Microsoft APIs responsibly, with minimal scopes and full user control.

Purpose-Limited Access

  • Data accessed only to provide the service (classification, drafting, sending)
  • No use of mailbox data for any purposes beyond service delivery
  • Clear disclosure of all scopes requested from users

No AI Model Training

  • No training of AI models on customer mailbox data — ever
  • Content processed ephemerally for reply generation
  • Customer data never used to improve third-party models

Minimal Scopes & Revocation

  • OAuth scopes minimized to the least permissions necessary
  • Access can be revoked at any time from Google/Microsoft account settings
  • Scopes publicly documented and regularly reviewed
Operations

Monitoring, Logging & Secure SDLC

Continuous visibility into our systems combined with secure development practices reduce risk across the board.

Centralized Monitoring

  • Centralized logging, alerting, and anomaly detection
  • Real-time dashboards with threshold-based alerting
  • Structured logs retained for forensic investigations

Secure Development (SDLC)

  • Mandatory code reviews for all production changes
  • Automated dependency monitoring and vulnerability scanning
  • Static analysis and dynamic testing integrated in CI/CD

Change Management

  • Approval gates required for all production deployments
  • Automated rollback capabilities and blue-green deployments
  • Change log maintained with full audit trail
Data Lifecycle

Data Retention & Deletion

We keep only what we need, only as long as we need it, with clear deletion workflows and backup controls.

Minimal Retention Principle

  • Data retained only as long as necessary for service delivery
  • Ephemeral processing for transient tasks — no persistent storage of email bodies
  • Automated deletion schedules enforced at the data layer

Account Deletion & Backups

  • Account-level deletion workflows: full data removal on request
  • Backups encrypted and held with strictly limited retention window
  • Deletion audited and confirmed in writing for enterprise accounts
Resilience

Incident Response

A documented incident response plan ensures we detect, contain, and recover from security events rapidly.

Documented IR Plan

  • Formally documented Incident Response (IR) plan
  • 24/7 on-call rotation for critical security incidents
  • Tabletop exercises conducted regularly to test readiness

Containment & Recovery

  • Defined containment, eradication, and recovery procedures
  • Automated isolation of affected components to limit blast radius
  • Post-incident reviews and root cause analysis documented

Customer Notifications

  • Customer notifications as required by law and contracts
  • Breach notifications within 72 hours as required by GDPR
  • Transparent post-mortems shared with enterprise customers
FAQ

Security FAQ

Key answers about Predimail's security and compliance.

Yes. Predimail operates under GDPR with user rights support and a Data Processing Addendum on request. Contact us at [email protected] to receive our DPA.
No. Data from Google/Microsoft APIs is processed only to provide the service and is not used to train or improve AI models. Email content is handled ephemerally and never stored for model training.
Predimail is CASA Tier 2 certified and maintains SOC 2–aligned controls including encryption, access management, logging, and incident response. We also maintain full GDPR compliance with DPA documentation available.
Ready to evaluate Predimail?

Review our Privacy Policy or contact us for a DPA and security questionnaire.

Our security team is available to answer questions and provide documentation for your compliance review.

CASA Tier 2 Certified GDPR Compliant SOC 2–Aligned Controls