How Muster protects
your mailbox.
We hold mailbox credentials, message bodies, and recipient lists. That is a serious responsibility. This page documents the encryption model, the worker boundary, the abuse controls, and how to reach our security team.
TLS terminates at the Fly.io edge. Services talk to each other over a private network.
Mailbox OAuth tokens and passwords are sealed with AES-GCM before they are stored.
Integration tokens and data passed between services are sealed with a key unique to your organization.
Envelope encryption, one key per organization.
Sensitive fields are sealed at the application layer before they reach the database. Mailbox OAuth tokens and passwords use a separate credentials key. Both keys are held outside the database, so a copy of the database alone does not reveal those fields.
A 256-bit master key is held as a deployment secret, outside the database. It never appears in a database row or a backup.
Each organization gets its own random 32-byte data key on first use. The master key seals it, and only the sealed copy is stored.
Integration and API tokens, and data queued between services, are sealed with AES-256-GCM using your organization's key.
Ciphertext and the sealed key are stored in Postgres. The unsealed key is cached in Redis for at most 15 minutes.
Workers do not touch your database.
Workers are the execution plane. They send and sync mail across many machines with separate network identities. They take commands over a NATS message bus and report results the same way. They never open a PostgreSQL connection.
That boundary matters. A worker cannot query the database; it reaches account data only through the backend's internal API. Messages on the bus are sealed with your organization's key.
What we hold, and what we refuse to hold.
Specifics, not slogans. If you do not see something on the left, we are probably not collecting it. If something on the right ever moves, we will say so on /changelog/.
- Account profile: email, name, organization.
- Mailbox credentials, encrypted at rest: OAuth tokens, IMAP and SMTP passwords.
- Sent and received messages for the mailboxes you connect.
- Recipient lists you upload or sync.
- Deliverability signals: bounces, complaints, replies, opens, clicks, suppression.
- Billing metadata via Stripe. Card data never touches our servers.
- Error reports from our services, sent without request bodies.
- Plaintext passwords. Account passwords are stored as argon2 hashes, and mailbox passwords are encrypted.
- Card numbers, CVCs, or full PAN. Stripe holds the payment instrument.
- Recipient browsing or off-platform behavior. Tracking covers your campaign mail only.
- Message text in session replays. Replays mask all text and block media.
- Cross-customer data sharing. Tenancy is enforced at the query layer.
Layered controls, not one brittle gate.
A cold email platform is only as safe as the slowest line of defense. We block early, dedupe everywhere, and keep an audit trail of admin actions.
Every warmup email carries a signed token, so pool mail is recognized and checked when it arrives.
A mailbox is quarantined from the shared pool at 20% spam placement and blocked for 30 days at 40%, a 0.30% complaint rate, a 10% bounce rate, or any tampering with pool mail.
Bounces, complaints and unsubscribes are written to suppression and enforced at send time. Campaigns skip suppressed recipients automatically.
Login, registration and password-reset requests are rate-limited per IP address.
API and WebSocket traffic are rate-limited per user against Redis-backed counters, with category-specific budgets per plan.
Tracking events deduplicate via in-memory and persistent caches. Stripe webhooks are deduplicated by event ID.
Who else touches your data.
The infrastructure and operational providers Muster relies on to run.
We give 30 days notice before adding any subprocessor that processes customer Personal Data.
Found something. Tell us first.
We welcome reports from security researchers and operators. Send a description, a proof of concept, and any logs through the contact page. We will acknowledge quickly, triage in the open, and keep you posted until the fix ships.
Please avoid testing that degrades service for other customers, accesses data that is not your own, or relies on social engineering of employees or contractors. Good faith research is welcome.
Want the full security package?
Data processing terms, security questionnaire, and architecture deep dive on request. Replies from a human within one business day.




