MAILRAFT

MAILRAFT / DOCS V1

Security

Tenant membership and suspension are checked server-side. Integration secrets are encrypted; sessions are host-only and redirects are allowlisted. Custom outbound requests validate DNS, pinned connections and every redirect, with timeout and response-size limits.

Campaigns, SMS and WhatsApp require explicit policy and approvals. No arbitrary remote MCP server is proxied. Security and provider acceptance gates remain visible in the status page; a healthy HTTP endpoint is not evidence of delivery.