Trust Portal

Security overview

All EmDash traffic and customer data in transit is encrypted over TLS via Cloudflare's edge network. Application data at rest is stored in dedicated, credential-scoped Postgres databases with row-level security, and background jobs authenticate with least-privilege, per-service database roles rather than a single shared credential.

Data security

How customer data is protected in transit, at rest, and over its lifecycle.

Encryption in transit

All traffic between browsers, EmDash's Cloudflare Workers, and backend services including database connections are encrypted with TLS.

Encryption at rest

Application and platform Postgres databases, and object storage (Cloudflare R2), are encrypted at rest by their respective infrastructure providers.

Backups

Application and platform databases run on PlanetScale-managed Postgres, which handles automated backups of hosted databases as part of its managed service.

Data retention & deletion

Stored objects are automatically deleted within 90 days. Objects can be deleted earlier on request.

Subprocessors

Third-party services that store or process customer data on EmDash's behalf, and where each one operates.

Subprocessor Purpose Data location
Cloudflare, Inc.
  • Edge compute (Workers) for all application and API traffic
  • Object storage (R2) for DMARC reports and incident evidence
  • Message queues for background job processing
  • Transactional email routing and sending
  • Workers AI (runs Google's Gemma model) for incident summarisation, executed entirely within Cloudflare's infrastructure
Global edge network
PlanetScale, Inc.
  • Primary Postgres database hosting for application data
  • Separate Postgres database hosting for the platform control plane
Sydney, Australia

Data locations

A quick reference for where EmDash-controlled customer data lives.

Application & platform databases

Sydney, Australia (PlanetScale Postgres)

Compute, static assets & queues

Cloudflare's global edge network, with no single fixed region

Microsoft 365 data

Remains in each customer's own Microsoft 365 tenant. EmDash accesses it via the Microsoft Graph API under the customer's own region and consent scope, and does not copy or relocate it outside that tenant.

Network

How requests move between EmDash, Cloudflare's edge network, and our database origin.