Learn how Kawaa protects your data.
Infrastructure security
- Encryption in transit - All API calls use TLS 1.2 or later
- Encryption at rest - Data encrypted with AES-256
- AWS hosting - Enterprise-grade infrastructure
Access control
- Role-based access control (RBAC)
- Two-factor authentication (2FA)
- Hardware security key support (FIDO2) - coming soon
- Audit log of account, security and billing actions (Enterprise plan)
Data handling
- Verification results are encrypted at rest and keyed by a one-way hash of the address
- Results are retained for your plan's retention period (7-365 days), then deleted
- Kawaa never reads your mailboxes; it only processes the addresses you submit
Security reporting
Found a vulnerability? Report it to security@kawaa.com. We acknowledge every report.