We safeguard your provider credentials and payload data with bank-grade encryption and zero-trust controls.
All API keys, credentials, and notification variables are encrypted at rest using AES-256 GCM. All API traffic is forced over TLS 1.3.
Third-party provider API keys (SES, Twilio, Meta) are stored in isolated cryptographic key vaults with zero plain-text logging.
Strict multi-tenant workspace partitioning ensures logical separation of customer data, logs, and routing configurations.
NotifySetu welcomes security researchers and ethical hackers to report vulnerabilities. If you discover a security flaw or potential bug, please report it to us immediately.