MailQuell

Security

Effective October 9, 2026

The lists you upload are other people's email addresses, so we treat them with care: we keep as little as we can, for as short a time as we can, and we protect your account as we would our own. This page describes what MailQuell does today.

1. Your account

  • Passwords are never stored: only a salted scrypt hash (OWASP-recommended settings). New passwords need at least 8 characters, a capital letter and a number.
  • Two-factor authentication with any authenticator app (TOTP), plus one-time recovery codes. A code can't be used twice. Admin accounts must use it.
  • Sign in with Google or Microsoft: an existing account is only linked when the provider proves you own the email address.
  • Brute-force protection: after 5 wrong passwords or codes in 15 minutes, sign-in is paused for that account, and every request is rate limited.
  • Sessions you control: see every signed-in device and its sign-in history, and sign any of them out from Account & Security. Session cookies are HttpOnly and can't be read by scripts.
  • Teams: give people their own login instead of sharing a password, with roles (owner, admin, member) that limit what each person can do.

2. Your lists and results

  • No email is ever sent to the addresses you check: the conversation with the mail server stops before any message.
  • The uploaded list is deleted when the check ends. Per-address results are deleted 20 days after the list finished; only the summary counts stay.
  • Download or delete everything: export all your data at any time, or delete your account with its lists and results.
  • AI lead qualification only reads the public website of each company; the email addresses and names in your list are never sent to the AI provider (see the DPA).

3. Encryption

  • Everything between your browser, our API and our servers travels over HTTPS (TLS), with HSTS.
  • Secrets are encrypted in the database with AES-256-GCM (two-factor secrets, webhook signing secrets).
  • API keys are stored as hashes: we show a key once, when you create it, and can't show it again.

4. API, webhooks and integrations

  • API keys can be read-only, revoked at any time, and never manage other keys or billing.
  • Webhooks are signed (HMAC-SHA256 with a timestamp), so your server can check that a call really comes from us and is not a replay.
  • The form widget only works on the website domains you allow, with daily limits.
  • Our mail-server checks never connect to private or internal network addresses.

5. Payments

Payments are handled by Paddle.com, our Merchant of Record. Your card details go straight to them: MailQuell never sees or stores card numbers.

6. Infrastructure and our team

  • Servers and database are hosted by OVHcloud in the United Kingdom, whose infrastructure is ISO/IEC 27001 certified. The website itself is served by Cloudflare (Cloudflare Pages).
  • The website sends strict security headers (Content-Security-Policy, no framing, no MIME sniffing).
  • Every action taken in the admin panel is recorded in an audit log.
  • MailQuell itself does not hold a security certification such as ISO/IEC 27001 or SOC 2 yet. We will say so here when it does.

7. Report a security problem

Found a vulnerability? Email support@mailquell.com with "Security" in the subject and the steps to reproduce it. Please give us a reasonable time to fix it before making it public, and don't access other people's data while testing. We reply to every report.

Our order process is conducted by our online reseller Paddle.com. Paddle.com is the Merchant of Record for all our orders and provides all customer service inquiries and handles returns.