Security
How we protect the Vaakio platform and the data our customers trust us with.
Last updated 21 September 2026
Our approach
Email platforms hold contact lists, so we treat customer data as something we are trusted to protect. This page describes the measures we apply. It is a summary, not a guarantee, and we continue to invest in it.
Infrastructure
- Hosted on Amazon Web Services (AWS), which maintains physical data-centre security and independent third-party certifications for its own infrastructure.
- Encryption in transit (TLS) between your browser or API client and Vaakio.
- Separation of customer data at the application level.
Access control
- Least-privilege access: staff can reach customer data only when needed for support or operations.
- Passwords are stored hashed, never in plain text.
- Authentication and session controls on the application.
Application security and monitoring
- Logging and monitoring of the platform for unusual activity.
- Abuse and deliverability monitoring, including spam-complaint and bounce tracking, to protect customers and recipients.
- Timely patching of systems and dependencies.
Incident response
If we confirm a breach affecting customer data, we notify affected customers without undue delay and, where GDPR applies, within 72 hours of becoming aware, with the information needed to meet their own obligations.
Your part
Use a strong, unique password, limit who has access to your account, remove people who leave your team, and keep your sending lists clean and permission-based.
Report a vulnerability
If you believe you have found a security issue, email security@vaakio.com with the details. Please give us reasonable time to fix it before disclosing it publicly, and do not access data that is not yours. We do not take legal action against good-faith research that follows this approach.
Related
Privacy Policy · Data Processing Addendum · Anti-Spam Policy