Snapshot 43668
Normalized text
Scripts and page chrome removed; this is what change detection compares.
One-on-one deliverability consultationOne-on-one free email deliverability consultationBookMeet a consultant Security & Trust Security is our highest priority Every customer we serve gets the same protection: encryption, least-privilege access and continuous monitoring. Talk to Our TeamBook a Demo SOC 2 Type II in progress | GDPR & CCPA aligned | Encrypted end to end Trusted by Fortune 500 companies SOC 2 Type II in progress GDPR & CCPA aligned AES-256 at rest · TLS 1.2+ in transit OAuth 2.0 - no passwords stored Data hosted in the EU (Ireland) Built for enterprise Security is not a feature, it is the foundation Fortune 500 companies, global agencies and regulated enterprises rely on Warmy with their production mailboxes. That trust sets the bar: every connection is encrypted, every access is scoped to the minimum needed, and every action is logged and reviewable. AES-256 Encryption at rest TLS 1.2+ Encryption in transit OAuth 2.0 No passwords stored 24/7 Infrastructure monitoring How we protect you Security controls across every layer From the moment a mailbox is connected to the day an account is closed, your data is handled under documented controls. Data protection Your content stays yours. We store only what is required to run warm-up, monitoring and deliverability analysis. AES-256 encryption at rest, TLS 1.2+ in transit Warm-up conversations are generated by Warmy, not taken from your inbox Data deleted on request and on account closure Access & authentication Mailboxes are connected through official provider flows, so credentials never sit in our database. OAuth 2.0 for Google Workspace and Microsoft 365 Tokens stored in an encrypted vault with scoped permissions SSO and 2FA available for enterprise workspaces Infrastructure Warmy runs on hardened cloud infrastructure with isolated environments and automated recovery. Segregated production, staging and development environments Encrypted, automated backups with tested restore procedures Continuous uptime, intrusion and anomaly monitoring Application security Every release passes automated and human review before it reaches your account. Peer-reviewed code and dependency vulnerability scanning Regular penetration testing by external specialists Role-based access control inside the product Privacy & compliance We align our processing with global privacy regulation and document how data flows through the platform. GDPR and CCPA aligned processing with DPA available Vetted sub-processors under contractual security obligations Data residency and retention options for enterprise plans Operations & response Security is a daily practice, not a yearly audit. Our team is trained, on call and accountable. Documented incident response with defined notification timelines Mandatory security training and background checks for staff Audit logs of administrative and account-level actions SOC 2 roadmap Our path to SOC 2 Type II We are running a five-month programme with an independent auditor. Here is exactly where we are and what comes next. Programme progress 3 of 5 phases underway or complete 60% M1M2M3M4M5 Month 1Completed Readiness assessment Gap analysis against the Trust Services Criteria, scoping of systems and selection of an independent audit partner. Month 2Completed Policies & controls Formal security, access, change-management and incident-response policies written, approved and rolled out company-wide. Month 3In progress Implementation & automation Continuous control monitoring, centralised logging, device management and evidence collection deployed across the stack. Month 4Next Observation window Controls run under audit observation while penetration testing and remediation close any remaining findings. Month 5Planned Audit & report Independent auditor fieldwork, final evidence review and issuance of the SOC 2 report, shared with enterprise customers under NDA. Enterprise customers can request our current security documentation and audit status at any time. Meet our security lead Your security review has a named owner No ticket queues, no generic inbox. Our security lead takes your questionnaire, DPA and architecture questions personally, answers with evidence rather than marketing claims, and stays with your team until procurement signs off. Enterprise reviews - Answers security questionnaires and vendor assessments end to end. SOC 2 programme - Owns the Type II roadmap, control evidence and auditor relationship. Contracts & incidents - Single point of contact for DPAs, sub-processors and response. FAQ Security Questions Warmy is in the middle of a five-month SOC 2 Type II programme with an independent auditor. Policies, controls and continuous monitoring are already implemented, and the audit report is scheduled at the end of the programme. Enterprise customers can request our current status and documentation at any time. Get started Security Reviews, Questionnaires And DPAs Our Team Will Walk You Through It Talk to Our Security TeamBook a Demo Enterprise onboarding support included