Security & Compliance
Last updated: April 8, 2026
PostBolt is built and operated with security in mind. This page summarises our approach to keeping your data safe. It complements the technical and organisational measures listed in Schedule 1 of our Data Processing Agreement.
Encryption Everywhere
TLS 1.2+ in transit, AES-256 at rest
Least-Privilege Access
Mandatory MFA and audit logs for all production access
GDPR / CCPA Ready
Transparent policies, user rights, and DPA on request
- In transit. All connections use TLS 1.2 or higher with modern cipher suites. HSTS is enabled on the website.
- At rest. Databases, object storage, and backups are encrypted using AES-256 or equivalent.
- Secrets. OAuth tokens, API keys, and other secrets are encrypted at the application layer using a managed key-management service. Secrets are never logged.