Keeping your mail private and safe is the whole point of Letter. This page summarises the measures we use to protect the Service and your data.
Encryption
- In transit: all connections to Letter use TLS. We support encrypted transport (STARTTLS) for mail to and from other providers.
- At rest: mailbox data and backups are encrypted on disk.
Account protection
- Passwords are stored only as salted, one-way hashes using a modern algorithm.
- We support two-factor authentication (2FA) for an extra layer of sign-in security.
- We monitor for suspicious sign-ins and can lock accounts on signs of compromise.
Infrastructure and access
- Systems run on hardened, regularly patched infrastructure with network isolation.
- Access to production data is limited to authorised staff on a least-privilege basis and is logged.
- We take regular, encrypted backups and test our ability to restore them.
Anti-abuse
We use spam and malware filtering, rate limiting and authentication standards (SPF, DKIM and DMARC) to protect your inbox and to keep the letter.click domain trustworthy.
Responsible disclosure
If you believe you have found a security vulnerability, please report it privately to security@letter.click. We welcome good-faith research, will investigate promptly, and will not pursue legal action against researchers who act responsibly and avoid harming users or data.
Incident response
We maintain an incident-response process and will notify affected users and regulators of a security breach as required by law. See our Privacy Policy for how we handle personal data.
← Back to letter.click