TrustOperational truth, not marketing.

How Muster protects
your mailbox.

We hold mailbox credentials, message bodies, and recipient lists. That is a serious responsibility. This page documents the encryption model, the worker boundary, the abuse controls, and how to reach our security team.

Posture
What we have shipped, and what is still planned.
Changelog
TLS in transit
Shipped

TLS terminates at the Fly.io edge. Services talk to each other over a private network.

Credentials encrypted at rest
Shipped

Mailbox OAuth tokens and passwords are sealed with AES-GCM before they are stored.

Per-organization data keys
Shipped

Integration tokens and data passed between services are sealed with a key unique to your organization.

Encryption model

Envelope encryption, one key per organization.

Sensitive fields are sealed at the application layer before they reach the database. Mailbox OAuth tokens and passwords use a separate credentials key. Both keys are held outside the database, so a copy of the database alone does not reveal those fields.

01
Root of trust
Master key

A 256-bit master key is held as a deployment secret, outside the database. It never appears in a database row or a backup.

02
AES-256
Per-organization key

Each organization gets its own random 32-byte data key on first use. The master key seals it, and only the sealed copy is stored.

03
Authenticated
AES-GCM seal

Integration and API tokens, and data queued between services, are sealed with AES-256-GCM using your organization's key.

04
Envelope
Ciphertext at rest

Ciphertext and the sealed key are stored in Postgres. The unsealed key is cached in Redis for at most 15 minutes.

Unsealed key cached in Redis, 15-minute TTL Sealed key stored in Postgres AES-256-GCM authenticated encryption
Worker boundary

Workers do not touch your database.

Workers are the execution plane. They send and sync mail across many machines with separate network identities. They take commands over a NATS message bus and report results the same way. They never open a PostgreSQL connection.

That boundary matters. A worker cannot query the database; it reaches account data only through the backend's internal API. Messages on the bus are sealed with your organization's key.

cmd/worker · network surface
PostgreSQL
never connected
never
NATS
commands in, results out
allowed
Backend API
keys and message data, private network
allowed
Object storage
message bodies and attachments
allowed
Redis
data-key cache, 15-minute TTL
allowed
Data handling

What we hold, and what we refuse to hold.

Specifics, not slogans. If you do not see something on the left, we are probably not collecting it. If something on the right ever moves, we will say so on /changelog/.

What we collect
  • Account profile: email, name, organization.
  • Mailbox credentials, encrypted at rest: OAuth tokens, IMAP and SMTP passwords.
  • Sent and received messages for the mailboxes you connect.
  • Recipient lists you upload or sync.
  • Deliverability signals: bounces, complaints, replies, opens, clicks, suppression.
  • Billing metadata via Stripe. Card data never touches our servers.
  • Error reports from our services, sent without request bodies.
What we never collect
  • Plaintext passwords. Account passwords are stored as argon2 hashes, and mailbox passwords are encrypted.
  • Card numbers, CVCs, or full PAN. Stripe holds the payment instrument.
  • Recipient browsing or off-platform behavior. Tracking covers your campaign mail only.
  • Message text in session replays. Replays mask all text and block media.
  • Cross-customer data sharing. Tenancy is enforced at the query layer.
Abuse and safety

Layered controls, not one brittle gate.

A cold email platform is only as safe as the slowest line of defense. We block early, dedupe everywhere, and keep an audit trail of admin actions.

Signed warmup mail

Every warmup email carries a signed token, so pool mail is recognized and checked when it arrives.

Auto-block thresholds

A mailbox is quarantined from the shared pool at 20% spam placement and blocked for 30 days at 40%, a 0.30% complaint rate, a 10% bounce rate, or any tampering with pool mail.

Suppression hygiene

Bounces, complaints and unsubscribes are written to suppression and enforced at send time. Campaigns skip suppressed recipients automatically.

Rate-limited sign-in

Login, registration and password-reset requests are rate-limited per IP address.

Per-user rate limiting

API and WebSocket traffic are rate-limited per user against Redis-backed counters, with category-specific budgets per plan.

Event idempotency

Tracking events deduplicate via in-memory and persistent caches. Stripe webhooks are deduplicated by event ID.

Subprocessors

Who else touches your data.

The infrastructure and operational providers Muster relies on to run.

Subprocessor
Purpose
Region
Fly.io
Hosting, TLS edge, private network
United States (Ashburn, VA)
Neon
Postgres database (runs on AWS)
United States (us-east-1)
Tigris
Object storage for messages and attachments
Global
Upstash
Redis caches and rate limits, via Fly.io
United States
Resend
Account email: sign-up, resets, invites
United States
Stripe
Billing and tax
United States
Anthropic
AI writing and reply features
United States
Sentry
Error reporting and masked session replays
United States
GitHub
Product feedback you choose to send
United States
Cloudflare
Turnstile CAPTCHA on hosted forms
Global

We give 30 days notice before adding any subprocessor that processes customer Personal Data.

Responsible disclosure

Found something. Tell us first.

We welcome reports from security researchers and operators. Send a description, a proof of concept, and any logs through the contact page. We will acknowledge quickly, triage in the open, and keep you posted until the fix ships.

Please avoid testing that degrades service for other customers, accesses data that is not your own, or relies on social engineering of employees or contractors. Good faith research is welcome.

Response SLA
Acknowledge
within 1 business day
Initial triage
within 3 business days
Status updates
every 7 days until resolved
Public credit
on request, after fix shipped

Want the full security package?

Data processing terms, security questionnaire, and architecture deep dive on request. Replies from a human within one business day.