Your customers' data deserves better
Security you can explain to a customer.
Dedicated database per workspace, encryption in transit and at rest, and the option to hold the keys yourself.
Encryption in transit
All traffic between you, Hatched Send and your database is protected by TLS 1.2+. No unencrypted hops, ever.
Encryption at rest
Subscriber data, template content and API keys are stored encrypted at rest on Neon and Cloudflare R2.
One database per workspace
Your contacts never sit in a shared list with other customers. We run a dedicated database for you. Want a region you choose? Plug in your own.
Hold the keys yourself
Want full control? Plug in your own database — your data, your project, a stronger GDPR and residency story. Available on every plan.
Authenticated sending
Send from your domain with SPF, DKIM and DMARC. No subdomain relays, no shared sender reputation.
Hashed credentials
Passwords are bcrypt-hashed. API keys are stored as SHA-256 hashes — we can never retrieve the raw value after creation.
Webhook signatures
Every webhook we send is signed; every Stripe webhook we receive is verified and idempotent.
Audit logs
Admin-sensitive actions (plan changes, key rotations, data deletions) are recorded to an append-only audit log.
Compliance without the enterprise theatre
Designed around GDPR, not around it.
We run a dedicated database for your workspace (we still process that data). Want a stronger GDPR or residency story? Plug in your own — you hold the project and pick the region.
Security questions
What security teams ask us.
In a dedicated database just for your workspace. We run that database for you to start. Want to hold the keys? Plug in your own database and pick the region.
Responsible disclosure.
Found a vulnerability? Email hello.digital with the subject “Security report”. We reply within one business day.
Trust, built in
The honest platform for email.
First 200 emails on us · Your Neon database · Cancel anytime.