Skip to main content

Security & privacy

Data security practices

Learn how Kawaa protects your data.

Infrastructure security

  • Encryption in transit - All API calls use TLS 1.2 or later
  • Encryption at rest - Data encrypted with AES-256
  • AWS hosting - Enterprise-grade infrastructure

Access control

  • Role-based access control (RBAC)
  • Two-factor authentication (2FA)
  • Hardware security key support (FIDO2) - coming soon
  • Audit log of account, security and billing actions (Enterprise plan)

Data handling

  • Verification results are encrypted at rest and keyed by a one-way hash of the address
  • Results are retained for your plan's retention period (7-365 days), then deleted
  • Kawaa never reads your mailboxes; it only processes the addresses you submit

Security reporting

Found a vulnerability? Report it to security@kawaa.com. We acknowledge every report.

Something wrong or missing here?

Tell us what to fix. Your email goes to the support team with this article's title already filled in.

Send feedback

Still need help?

Email support@kawaa.com. If your question is about a bulk job, include its job ID from the dashboard.

Contact support