Built by offensive security practitioners for security teams, delivr.to was designed with a defensive mindset and security baked in at multiple layers. This page provides an overview of the controls, processes and architecture choices that protect our customers and their data.
Security at delivr.to starts with the people running it. Founders James Coote and Alfie Champion are career offensive security and purple teaming practitioners - security posture is a default, not a feature.
Customer data, payloads and email artefacts are encrypted, isolated and auto-pruned. Sensitive material like attachments and raw email files is held against customer-managed KMS keys.
Authentication and authorisation are enforced consistently at the API edge, not in scattered handlers. Every request to a protected endpoint is checked against a central policy store before any business logic runs.
delivr.to is a UK-based company and operates entirely from AWS infrastructure in the United Kingdom. Customer data does not leave the UK region under normal operation.
delivr.to runs entirely on Amazon Web Services. AWS is ISO/IEC 27001, SOC 1/2/3, PCI DSS and HIPAA-attested, with a global footprint of physically secured data centres covered by 24/7 access monitoring, perimeter controls, video surveillance and intrusion detection.
If you believe you have found a security issue affecting delivr.to or any of its services, please email security@delivr.to. We will acknowledge your report within two business days, keep you updated as we investigate, and credit you on a public acknowledgements page if you wish. Please give us a reasonable window to remediate before any public disclosure.
Let's chat! We'll find the best solution for your security testing needs.