Data security
The security of your customers’ data is our top priority. We use use strict safeguards to protect it and prevent any unauthorized access.
Data Protection Measures
Although we cannot disclose every detail of our security setup, you can safely assume the following measures are in place:
- All data (including databases and in-transit) is encrypted.
- Encrypted backups are maintained and stored off-site.
- All servers operate on a public cloud provider (AWS) and are physically inaccessible to unauthorized individuals.
- All employees sign NDAs and complete mandatory security awareness training.
Data Center Security
Our platform is hosted on Amazon Web Services (AWS), which provides industry-leading cloud infrastructure with built-in security and compliance. AWS data centers are highly secure, continuously audited, and certified against global standards like ISO 27001 and SOC 2.
Customers benefit from a shared responsibility model, robust tools, and scalable protection designed for even the most security-sensitive environments.
Penetration Testing
We perform annual penetration tests to identify and address potential vulnerabilities. This proactive approach helps maintain a secure, reliable, and compliant email platform, giving customers greater confidence that their data is protected.
Security and Monitoring Practices
Moosend’s platform is designed with strong operational security to ensure integrity and uptime. We continuously monitor systems with advanced tools, conduct regular audits, and follow strict incident response protocols to quickly address potential risks.
Certifications
We maintain ISO/IEC 27001 certification for our Information Security Management System (ISMS). ISO/IEC 27001 is an internationally recognized standard that defines requirements for establishing, implementing, maintaining, and continually improving an information security management system designed to protect the confidentiality, integrity, and availability of information.
Moosend complies with applicable Payment Card Industry Data Security Standard (PCI DSS) requirements. Payment card information is processed using secure, industry-standard controls and handled in accordance with PCI DSS obligations.