Safe is in our name.

SafeReact exists to make email programs safer. We hold our own platform to the same standard. Here is how we protect your data and your systems.

Contact Security

Infrastructure security

SafeReact runs on Amazon Web Services in the US West (Oregon) region. Application services run in isolated containers on AWS ECS Fargate, and customer data is stored in Amazon Aurora PostgreSQL. All infrastructure is defined and deployed as code with Terraform, so every change is reviewed, versioned, and repeatable. Our consumer privacy request service runs in a separate, isolated AWS account.

Encryption

Data in transit: All traffic to and from SafeReact is encrypted with TLS 1.2 or higher.

Data at rest: Databases, backups, and file storage are encrypted with AES-256 using AWS Key Management Service. Enterprise customers can be provisioned with dedicated encryption keys, allowing their data to be cryptographically destroyed on request.

Tenant isolation and access control

Every customer's data is isolated at the database level using row-level security scoped to their organization. Customer sign-in is handled by WorkOS, with enforced password complexity and support for single sign-on. Internal access to production systems uses centralized single sign-on, multi-factor authentication, and least-privilege roles, and is reviewed regularly.

How we handle your data

We process the lists you upload to deliver hygiene and reactivation scoring, and nothing else. Results sync back to your email platform only through connections you authorize with OAuth, and you can disconnect them at any time. Access to customer data is limited to personnel who need it to operate the service.

Secure development

All code changes go through version control and peer review before release. Development, staging, and production are separate environments. We conduct independent third-party penetration testing and remediate findings on defined, severity-based timelines.

Monitoring and incident response

Our security controls are monitored continuously through Vanta. AWS activity is logged for audit and investigation. We maintain a documented Incident Response Plan that defines roles, severity levels, escalation paths, and remediation timelines, and we test it regularly.

Compliance

SOC 2 and ISO 27001: We are building our SOC 2 Type 2 and ISO 27001 programs with Vanta, with audits targeted for 2027.

Privacy law: FourLeaf LLC, which operates SafeReact, is a registered data broker in California and honors consumer requests under the CCPA, including requests submitted through California's Delete Request and Opt-out Platform (DROP).

Policies: We maintain a full set of approved information security policies, reviewed at least annually. Copies are available to customers and prospects under NDA.

Questions or reports

To request security documentation, complete a security questionnaire, or report a vulnerability, email security@safereact.com.

Consumers with privacy requests can visit our Privacy Policy.

This page is maintained by SafeReact's Head of Technology and reviewed quarterly. Last reviewed: October 2026.