Email is a trust business. Here is how we protect your account, your tokens and the messages flowing through PostedApi.
Last updated: September 2026
Every connection to PostedApi uses TLS 1.2 or newer, and stored data is encrypted with AES-256. Passwords and tokens are additionally hashed or encrypted in our database.
Add a second factor to every sign-in with TOTP-based two-factor authentication. We recommend it for everyone and require it for administrator roles.
Lock each server token to the IP ranges you choose. Requests from anywhere else are rejected before they ever reach your streams.
Independent security researchers probe our platform at least once a year, and every finding is triaged within 24 hours of confirmation.
Found a vulnerability in PostedApi? We would genuinely like to hear about it. Send a description and, if possible, the steps to reproduce it to [email protected].
We acknowledge every report within 48 hours, keep you informed while we investigate, and credit you publicly if you want us to.
Security is a process, not a badge. Here is where we stand on the formal frameworks: