Thumela • Security
Security, stated plainly
The controls Thumela implements today, the providers involved and the assurances we do not currently offer.
Email carries personal information. Here is how we handle it today, and where our current boundaries are.
Controls in place
- Recipient-address encryption. Recipient addresses are encrypted with AES-256-GCM before database storage. Address lookups use keyed HMAC-SHA256 hashes.
- Bodies held in memory. HTML, plain text and raw MIME bodies live in the API’s memory while sending and retrying. They are not persisted by the application. Pending messages fail if that process restarts.
- Transport encryption. Public site and API endpoints use HTTPS. Private-network SMTP requires STARTTLS before authentication.
- Region-scoped AWS permissions. Sending and event-processing credentials are scoped to AWS
af-south-1. - Restricted administration. Admin sign-in uses magic links and an email allowlist. This is not a claim of multi-factor authentication.
- Suppression before sending. Hard bounces and complaints create suppression entries checked before subsequent sends.
- Limited logging. The API logger redacts email-shaped values. Message bodies are not included in application log calls.
These controls apply to specific parts of the system. Recipient-address encryption does not mean every database field is encrypted individually.
Providers and their roles
| Provider | Location | Role |
|---|---|---|
| xneelo | Johannesburg, South Africa | Application and database hosting |
| Amazon Web Services | Cape Town, af-south-1 |
SES sending and SNS/SQS delivery-event processing |
The recipient’s own mail provider receives the message during delivery and may process it elsewhere. See the full residency statement.
What is not yet true
Thumela does not currently offer SOC 2 or ISO 27001 certification, a published SLA, or a public status page. We do not claim an independent security audit or penetration test. There is no availability or delivery-time guarantee.
Privacy and retention
Message records and events are retained for 90 days. Suppression entries are retained to prevent unwanted future sends. The waitlist has its own retention rules in the privacy notice.

