Security FAQ

This section provides quick answers to common questions about security at MessageFlow. For more detailed information, please refer to the relevant sections of our Trust Center.

General Security & Compliance

chevron-rightWhat are MessageFlow's key security certifications?hashtag

We hold several internationally recognised certifications, including ISO 27001 for Information Security Management, ISO 27018 for Personal Data Protection in the Cloud, and ISO 22301 for Business Continuity Management. We are also a member of the Certified Senders Alliance (CSA). You can learn more in our Certifications & Audits section.

chevron-rightWhere is my data physically stored?hashtag

All customer data is stored in secure, certified data centres located within the European Economic Area (EEA). We partner with industry-leading providers to ensure the highest level of physical security. For a full list of our infrastructure partners, see the Sub-processors section.

chevron-rightHow does MessageFlow comply with GDPR?hashtag

We are fully committed to GDPR compliance. As your Data Processor, we process data only on your behalf. Our responsibilities are formalised in our Data Processing Agreement (DPA). You can find more details in the Data Protection & Compliance section.

chevron-rightCan I sign a Data Processing Agreement (DPA)?hashtag

Yes. The DPA, an appendix to our Framework Agreement, is an integral part of our terms of service. To review or sign a copy, please contact our support teamarrow-up-right.

Account Security

chevron-rightWhat is the single most effective way to secure my account?hashtag

Enabling Two-Factor Authentication (2FA) is the best step you can take. It provides a powerful second layer of security, even if your password is compromised.

chevron-rightCan I restrict who can log in to my account?hashtag

Yes. We highly recommend using the IP Access Control feature to whitelist specific IP addresses for panel, and IP Authorization for SMTP serversarrow-up-right. You can also manage team access through User and role management.

chevron-rightWhat should I do if I suspect my account has been compromised?hashtag

Act immediately. First, reset your passwordarrow-up-right. Second, review the list of active users in your account and check for any unrecognized activity. Finally, contact our support teamarrow-up-right right away so we can help you investigate.

Platform & Sending Security

chevron-rightIs my data encrypted?hashtag

Yes. We use encryption to protect your data both in transit (using protocols like TLS) and at rest (while stored on our servers). You can find more details in the Data & Infrastructure Security and Email Communication Security sections.

chevron-rightWhy is Sender Authorization (SPF, DKIM, DMARC) so important?hashtag

These protocols are essential for email deliverability and brand protection. They prove to receiving mail servers that you are a legitimate sender, which prevents your emails from being marked as spam and protects your brand from being impersonated by phishers. Learn more in our Senders Authorizationdocumentation.

chevron-rightHow does MessageFlow protect against phishing and SMS fraud?hashtag

Our proprietary Shield 360 technology provides real-time protection against threats by analysing links and monitoring traffic in collaboration with security partners like CERT Polska and Google Safe Browse.

chevron-rightHow do I report abuse or spam?hashtag

If you receive a suspicious message sent from our platform, please forward it to our support team for investigation. For general smishing, we recommend reporting it to a national body like CERT Polska. Find more details in the Abuse Policy and Reporting section.

Last updated