Infrastructure
- Cloud hosting. Coldbean runs on enterprise cloud infrastructure in data centers holding industry certifications (ISO 27001, SOC 2). We do not operate physical servers; physical security is managed by our providers.
- Edge protection. All traffic passes through a hardened edge with WAF rules, DDoS mitigation, and rate limiting.
- Network segmentation. Production systems are isolated from development and internal tooling. Administrative access to production is restricted to a private network over VPN.
- Environment separation. Production data is not used in development or staging environments except where strictly necessary, and then under equivalent protections.
Data Protection
- Encryption in transit. All connections to Coldbean use TLS 1.2 or higher. Internal service-to-service traffic is encrypted.
- Encryption at rest. Databases, object storage, and backups are encrypted at rest using AES-256 or equivalent.
- Secrets and tokens. OAuth tokens for connected Google Workspace and Microsoft 365 accounts, API keys, and credentials are encrypted with restricted-access keys and are never written to logs.
- Tenant isolation. Customer workspaces are logically separated; every data access is scoped to the authenticated tenant.
- Data minimization. We request only the OAuth scopes required for the features you enable, and you can revoke connected-account access at any time from your provider's console or from Coldbean settings.
Access Control
- Least privilege. Employee access to production systems and customer data is granted per role, on a need-to-know basis, and reviewed periodically.
- Authentication. Multi-factor authentication is enforced for all administrative and infrastructure access. Shared accounts are prohibited.
- Offboarding. Access is revoked promptly when roles change or personnel depart.
- Customer-side controls. Coldbean supports role-based permissions within workspaces, so you control which of your users can access mailboxes, pipelines, and settings.
Application Security
- Secure development. Code changes go through review before deployment. CI pipelines run automated tests, dependency audits, and vulnerability scanning.
- Patching. Dependencies and base images are monitored for known vulnerabilities and patched on a prioritized schedule; critical vulnerabilities are remediated on an expedited basis.
- Penetration testing. We engage independent testing of the application and infrastructure periodically and remediate findings by severity.
- API security. All API access is authenticated, authorized per tenant, and rate-limited.
Monitoring and Logging
Centralized, tamper-resistant logging of authentication events, administrative actions, and data access.
Automated alerting on anomalous activity, error spikes, and availability degradation.
Logs are retained long enough to support security investigations, then purged.
Availability and Resilience
Redundant infrastructure across availability zones.
Automated, encrypted backups with defined retention and periodic restore testing.
Documented disaster-recovery procedures with defined recovery objectives.
Status and incident communications provided to affected customers during significant events.
Incident Response
We maintain a documented incident-response plan covering detection, triage, containment, eradication, recovery, and post-incident review. If a personal data breach affects your data, we notify you without undue delay — and within 72 hours where the GDPR applies — with the details required for your own notification obligations, per our DPA.
Vendor Security
Subprocessors are vetted for security posture before engagement, bound by data-protection agreements, and reviewed periodically. Our current subprocessor list is available via the DPA.
Compliance
- GDPR / UK GDPR: processor commitments, SCCs for international transfers, and a signable DPA available to all customers.
- CCPA/CPRA: we act as a service provider for Customer Data and do not sell or share personal information.
- Google API Services User Data Policy: our use of Google user data complies with the Limited Use requirements.
- Certifications and audit reports, as they are completed, will be listed here and made available under NDA on request.
Your Responsibilities
Security is shared. Customers are responsible for: strong, unique passwords and enabling MFA; managing user roles and removing departed team members; securing connected third-party accounts; and lawful, compliant use of email features.
Reporting a Vulnerability
If you believe you've found a security vulnerability in Coldbean, email support@coldbean.ai with reproduction details. We ask that you avoid accessing other customers' data, give us reasonable time to remediate before disclosure, and refrain from destructive testing. We do not pursue legal action against good-faith research conducted under these guidelines.
Security contact: support@coldbean.ai
Privacy contact: tim@coldbean.ai
See our DPA for contractual security commitments and our Privacy Policy for data handling practices.