Your customers' data deserves better

Security you can explain to a customer.

Dedicated database per workspace, encryption in transit and at rest, and the option to hold the keys yourself.

Encryption in transit

All traffic between you, Hatched Send and your database is protected by TLS 1.2+. No unencrypted hops, ever.

Encryption at rest

Subscriber data, template content and API keys are stored encrypted at rest on Neon and Cloudflare R2.

One database per workspace

Your contacts never sit in a shared list with other customers. We run a dedicated database for you. Want a region you choose? Plug in your own.

Hold the keys yourself

Want full control? Plug in your own database — your data, your project, a stronger GDPR and residency story. Available on every plan.

Authenticated sending

Send from your domain with SPF, DKIM and DMARC. No subdomain relays, no shared sender reputation.

Hashed credentials

Passwords are bcrypt-hashed. API keys are stored as SHA-256 hashes — we can never retrieve the raw value after creation.

Webhook signatures

Every webhook we send is signed; every Stripe webhook we receive is verified and idempotent.

Audit logs

Admin-sensitive actions (plan changes, key rotations, data deletions) are recorded to an append-only audit log.

Compliance without the enterprise theatre

Designed around GDPR, not around it.

We run a dedicated database for your workspace (we still process that data). Want a stronger GDPR or residency story? Plug in your own — you hold the project and pick the region.

Security questions

What security teams ask us.

In a dedicated database just for your workspace. We run that database for you to start. Want to hold the keys? Plug in your own database and pick the region.

Responsible disclosure.

Found a vulnerability? Email hello.digital with the subject “Security report”. We reply within one business day.

Trust, built in

The honest platform for email.

First 200 emails on us · Your Neon database · Cancel anytime.