Trust
Security overview
Last updated: July 31, 2026 · Honest pre-launch status
No compliance seals we haven’t earned. What’s true today vs planned at open.
Today (this website + early access)
- TodayHTTPS with HSTS; security headers (CSP, X-Content-Type-Options, frame protections).
- TodayEarly-access form: email (required), optional name/interest; honeypot anti-spam; stored for launch contact only.
- TodayNo self-serve document upload for production mailing on this Site yet.
- TodayPhone and email to Broadstroke / mail ops staffed for human conversations.
At platform open (planned)
- PlannedAccount authentication and prepaid meter funding before jobs produce.
- PlannedHuman approval before production on the AI-assisted setup path.
- PlannedTransport encryption for portal traffic; access controls for production systems.
- PlannedDocument and recipient data handled in the production environment used by the Postalocity stack — details available under NDA / security questionnaire for qualified buyers.
- PlannedMCP for agents: account-tied access; no anonymous free mailing; standalone public API keys planned later.
What we will not claim
- Not claimedLive SOC 2 Type II (or other) certification for USMail.ai unless we publish a real report.
- Not claimedHIPAA BAA availability until a signed program exists and is offered in writing.
- Not claimedThat self-serve mail production is live today.
Request a security conversation
Procurement and security teams: call 888-667-5322 or 316-247-5300, or email info@usmail.ai. Ask for mail ops / security questionnaire support.