Security

Messaging control matters more when the product becomes a workflow system.

This page focuses on the controls already present in the platform: scoped access, admin-session wrapping, sender constraints, audit surfaces, signed events, and retention posture.

API keys are required for send endpoints and can be rotated from the dashboard.

Credit limits are enforced by plan so sandbox and production accounts cannot silently overrun usage.

Admins can manage sender status, billing recovery, and workspace security from authenticated dashboard flows.

SSO and stronger workspace controls are reserved for the Business tier where they fit the current product direction.

The product should stay positioned for opted-in customer communication, not spam or cold outreach.