Last updated: July 1, 2026
1. Security Program
Security at MessageCrafts is a dedicated engineering discipline, not a checkbox. Our program covers infrastructure security, application security, corporate security, and compliance — governed by policies reviewed at least annually and enforced through automated controls.
2. Data Protection
- All customer data is encrypted in transit using TLS 1.2 or higher.
- Data at rest is encrypted with AES-256; keys are rotated and managed in a hardened KMS.
- Message content is retained only as long as needed for delivery and reporting, then purged per customer configuration.
- Production data access requires just-in-time approval and is fully logged.
3. Application Security
- Secure development lifecycle with mandatory code review and static analysis on every change.
- Dependency and container scanning in CI with automated patching SLAs.
- Annual third-party penetration tests, with findings tracked to closure.
- Web application firewalls and adaptive rate limiting on all public endpoints.
4. Platform Abuse Prevention
Our fraud systems analyze traffic in real time to detect SMS pumping, phishing patterns, and anomalous sending behavior — protecting both our customers' budgets and message recipients.
5. Incident Response
A 24/7 on-call security team operates a documented incident response process with defined severity levels. Customers are notified of incidents affecting their data without undue delay and in accordance with applicable law and contractual commitments.
6. Business Continuity
Services run active-active across multiple regions with automated failover. Backups are taken continuously, stored encrypted in separate fault domains, and restore procedures are tested quarterly.
7. Responsible Disclosure
We welcome reports from security researchers. If you believe you've found a vulnerability, email security@messagecrafts.com with reproduction details. We commit to acknowledging reports within two business days and will not pursue legal action for good-faith research conducted within our disclosure guidelines.
