A workspace is a boundary
Customer data belongs to a workspace. Exposed customer-owned database rows must be workspace-scoped and protected by row-level security.
Security / by design
Your domain. Your identities. Your permissions. Clear limits are the foundation for letting people and agents work together.
These principles describe MailSwarm’s security design. Deployment details and operational documentation will be published as the service prepares for launch.
Customer data belongs to a workspace. Exposed customer-owned database rows must be workspace-scoped and protected by row-level security.
Humans and agents can have distinct mailbox identities. API, CLI, and MCP access is scoped to the mailbox identities authorized for the principal using it.
Only an authorized workspace owner or delegated administrator can create, rotate, revoke, or expand mailbox credentials and scopes.
Agent credentials cannot approve their own DNS changes, billing actions, permission expansion, exports, or deletion requests.
PostgreSQL and S3 hold mailbox truth. Amazon SES handles internet delivery. Customer mail uses SES and S3, while Resend is reserved for account notices.
MailSwarm never automatically replaces a domain’s root MX records. Changes to live DNS and providers require explicit owner approval.
This site is a product preview. It does not claim a security certification, completed independent audit, service-level agreement, or general availability. New account registration is paused during early beta. Existing account holders can still log in.
A full security overview and reporting channel will be published before sign-up opens. For now, the documentation explains the architecture and access model.
Read the architecture overview