Remix.run Logo
reassess_blind 12 hours ago

Looks good. How’s your security? These days everything hinges on email for auth (particularly with email code sign in being so popular) so if there is a breach that’s a lot of exposure. Security is the one aspect that would make me hesitant to try a newcomer email API.

tmcemag 11 hours ago | parent [-]

Matt from Anypost here :)

Great question and I'm happy to speak at least from the non-engineering perspective. The platform is designed such that we don't retain any customer data, we only process the email transactions, so that helps with the blast radius a bit.

We're also in the process of beginning our SOC2 audit to add some confidence through that lens.

Our team previously built a few products in email, including an end-to-end encrypted email service for regulated customers, so there's a lot we've learned and done in the past that informs how we build secure products today. I've also personally built compliance and security product strategy for large developer products which means security is a first-class discipline for us.

Dan, I'm sure, would be happy to go into more specific, technical detail but I hope this information is helpful still.