Protection in layers.
Clarity at every step.

Security is a chain of boundaries across transport, identity, sessions, recovery, application secrets, and mailbox operations.

Defense model

No single control carries the whole security claim.

01

Protect the connection

HTTPS and supported mail protocols use authenticated TLS. Certificate verification remains enabled in runtime code.

transport
02

Protect the account

Passwords, MFA readiness, passkeys, bounded recovery, CSRF, and session rotation answer different threats.

identity
03

Minimize stored secrets

Reset tokens and backup codes are stored as hashes. Recoverable secrets require authenticated encryption.

data

Strong sign-in without a fragile recovery shortcut.

Each layer answers a different risk: passwords establish a secret, authenticators add proof, passkeys resist phishing, and recovery methods must be verified before use.

PasskeysAuthenticatorHashed backup codesRevocable sessions
ACCOUNT / SECURITY STATE
Layered protectionControls remain independently inspectable
READY
  • Primary sign-inprotected
  • Recovery methodsverified only
  • Active sessionsrevocable
  • Security activityauditable

A technical view of the trust boundaries.

Protection is attached to a specific asset, mechanism, and visible outcome.

BoundaryPrimary controlVisible resultScope
TransportAuthenticated TLSConnection statusnetwork
SessionRotation + CSRFRevocable devicesapplication
RecoveryExpiring hashed tokensVerified methodsidentity
SecretsHash or authenticated encryptionNo raw token storagedata
MailboxProvider capability stateApplied / pending / failedservice

Encryption is not one switch.

Transport, stored application secrets, mailbox storage, and end-to-end message encryption are separate layers. Claims must match the deployed architecture.

NETWORK

In transit

TLS protects supported network connections against passive interception.

ProtectsThe connection path
STORAGE

At rest

Protection depends on database, application encryption, and mail-server deployment.

Depends onThe stored asset
CONTENT

Message content

End-to-end encryption is claimed only where sender and recipient cryptography is implemented.

RequiresEnd-to-end key behavior

Choose limits with the same level of clarity.

Each active public plan is joined to one current price while earlier Stripe Price mappings remain in history.

View pricing