One-on-one deliverability consultationBook
Security & Trust

Security is our
highest priority

Every customer we serve gets the same protection:
encryption, least-privilege access and continuous monitoring.

SOC 2 Type II in progress | GDPR & CCPA aligned | Encrypted end to end

  • Trusted by Fortune 500 companies
  • SOC 2 Type II in progress
  • GDPR & CCPA aligned
  • AES-256 at rest · TLS 1.2+ in transit
  • OAuth 2.0 - no passwords stored
  • Data hosted in the EU (Ireland)
Built for enterprise

Security is not a feature, it is the foundation

Fortune 500 companies, global agencies and regulated enterprises rely on Warmy with their production mailboxes. That trust sets the bar: every connection is encrypted, every access is scoped to the minimum needed, and every action is logged and reviewable.

AES-256
Encryption at rest
TLS 1.2+
Encryption in transit
OAuth 2.0
No passwords stored
24/7
Infrastructure monitoring
How we protect you

Security controls across every layer

From the moment a mailbox is connected to the day an account is closed, your data is handled under documented controls.

Data protection

Your content stays yours. We store only what is required to run warm-up, monitoring and deliverability analysis.

  • AES-256 encryption at rest, TLS 1.2+ in transit
  • Warm-up conversations are generated by Warmy, not taken from your inbox
  • Data deleted on request and on account closure

Access & authentication

Mailboxes are connected through official provider flows, so credentials never sit in our database.

  • OAuth 2.0 for Google Workspace and Microsoft 365
  • Tokens stored in an encrypted vault with scoped permissions
  • SSO and 2FA available for enterprise workspaces

Infrastructure

Warmy runs on hardened cloud infrastructure with isolated environments and automated recovery.

  • Segregated production, staging and development environments
  • Encrypted, automated backups with tested restore procedures
  • Continuous uptime, intrusion and anomaly monitoring

Application security

Every release passes automated and human review before it reaches your account.

  • Peer-reviewed code and dependency vulnerability scanning
  • Regular penetration testing by external specialists
  • Role-based access control inside the product

Privacy & compliance

We align our processing with global privacy regulation and document how data flows through the platform.

  • GDPR and CCPA aligned processing with DPA available
  • Vetted sub-processors under contractual security obligations
  • Data residency and retention options for enterprise plans

Operations & response

Security is a daily practice, not a yearly audit. Our team is trained, on call and accountable.

  • Documented incident response with defined notification timelines
  • Mandatory security training and background checks for staff
  • Audit logs of administrative and account-level actions
SOC 2 roadmap

Our path to SOC 2 Type II

We are running a five-month programme with an independent auditor. Here is exactly where we are and what comes next.

Programme progress

3 of 5 phases underway or complete

60%
M1M2M3M4M5
  1. Month 1Completed

    Readiness assessment

    Gap analysis against the Trust Services Criteria, scoping of systems and selection of an independent audit partner.

  2. Month 2Completed

    Policies & controls

    Formal security, access, change-management and incident-response policies written, approved and rolled out company-wide.

  3. Month 3In progress

    Implementation & automation

    Continuous control monitoring, centralised logging, device management and evidence collection deployed across the stack.

  4. Month 4Next

    Observation window

    Controls run under audit observation while penetration testing and remediation close any remaining findings.

  5. Month 5Planned

    Audit & report

    Independent auditor fieldwork, final evidence review and issuance of the SOC 2 report, shared with enterprise customers under NDA.

Enterprise customers can request our current security documentation and audit status at any time.

Alex, Warmy security lead, who handles security reviews, DPAs and the SOC 2 Type II programme
Meet our security lead

Your security review has a named owner

No ticket queues, no generic inbox. Our security lead takes your questionnaire, DPA and architecture questions personally, answers with evidence rather than marketing claims, and stays with your team until procurement signs off.

  • Enterprise reviews - Answers security questionnaires and vendor assessments end to end.

  • SOC 2 programme - Owns the Type II roadmap, control evidence and auditor relationship.

  • Contracts & incidents - Single point of contact for DPAs, sub-processors and response.

FAQ

Security
Questions

Warmy is in the middle of a five-month SOC 2 Type II programme with an independent auditor. Policies, controls and continuous monitoring are already implemented, and the audit report is scheduled at the end of the programme. Enterprise customers can request our current status and documentation at any time.

Get started

Security Reviews, Questionnaires And DPAs
Our Team Will Walk You Through It

Enterprise onboarding support included