Skip to content

Trust

Security

How PUBSONAR protects your team’s data: per-company isolation and encryption, two-factor sign-in, role-based visibility, an audit log and hosting in the EU.

01

Data isolation

Each company on PUBSONAR has its own workspace. Data never mixes between companies.

  • Every record belongs to one company and is filtered by it on every request
  • Stored credentials, such as mailbox tokens, are encrypted with a key per company
  • Platform staff do not send from customer accounts

02

Sign-in

Accounts are created by invitation only. There is no public sign-up.

  • Passwords stored as bcrypt hashes
  • Two-factor sign-in with backup codes
  • Signed-in devices listed in your security settings
  • Rate-limited sign-in and password reset

03

Roles and visibility

People see what their role and position allow.

  • Roles for admins, supervisors and account managers
  • Managers see the people below them in the reporting lines
  • Nobody can send from another person’s mailbox or phone

04

Mailbox access

Gmail is connected with Google’s own sign-in flow.

  • PUBSONAR never sees Gmail passwords
  • Access can be revoked from the Google account at any time
  • Mail is sent only when a person presses send

05

Audit and operations

Administrative actions and background jobs are recorded.

  • Audit log of administrative actions
  • System log of background jobs
  • Daily backups

06

Hosting

PUBSONAR runs in the EU.

  • Servers in Frankfurt, Germany
  • Traffic encrypted with TLS and served through Cloudflare
  • Security reports: [email protected]

Questions from your security team?

Send them to us; we answer in writing.