MessageFlow
MessageFlowPricingBlogAPI docs
EN
EN
  • MessageFlow Documentation
  • 🚀ACCOUNT
    • Dashboard
    • User panel
      • Settlements
      • Settings
        • Security
        • IP Authorization
        • Two-Factor Authentication (2FA)
        • API
        • Webhooks
      • Notifications
      • Operation list
      • File manager
      • GDPR
    • Login and account management
      • How to create an account?
      • Logging into the platform
      • Resetting the password
      • Changing your password in the App
      • Two-step authentication (2FA)
      • Resetting 2FA Settings
    • User and role management
      • Adding a user
      • Assigning permissions
      • User account activation
      • Editing and deleting a user
  • 💬CONTACTS
    • Adding contacts
      • Adding contacts manually
      • Importing contact lists (CSV, Excel)
      • Additional fields
    • Segmentation of customers
    • Archiving groups
  • Deleting groups
  • ✨COMMUNICATION CHANNELS IN THE PANEL
    • E-mail
      • Overview
      • Dashboard
      • Campaigns
        • Campaign list
        • Exporting campaigns from the list
        • Creating e-mail campaigns
          • Designing messages with a drag-and-drop editor
          • Email creation specifications
          • Personalizing email campaigns
          • Creating and downloading message templates
        • Booster for e-mail campaigns
          • Instructions for sending an e-mail campaign with the Booster option
          • Reports & analytics
      • Analytics, audiences and reports
        • Monitoring deliverability, opens, clicks
        • Storage of email campaign reports
        • Email address archiving, removing hard-bouncing addresses, unsubscribes
      • Outgoing
        • Outgoing List
        • Export list
      • Settings
        • Adding a sign-out page
    • SMS
      • Overview
      • Dasboard
      • Campaigns
        • Campaign list
        • Exporting campaigns from the list
        • Creating SMS campaign
        • Booster for SMS campaign
          • Instructions for sending an SMS campaign with the Booster option
          • Reports & analytics
      • Analytics, audiences and reports
        • Reporting and analysis of SMS campaign results
        • Storage of SMS campaign data
        • Archiving recipients, removing recipients with ERROR status
      • Incoming
        • List of incoming
        • Export list
      • Outgoing
        • Outgoing list
        • Export list
      • Settings
        • List of links with suffixes
        • Unsubscribe pages
      • Common settings
        • Sender IDs
      • Integration with short codes
      • SMS Billing
    • Mobile push
      • Overview
      • Dashboard
      • Campaigns
        • Campaign list
        • Export list
        • Push campaign configuration
        • Booster for mobile push campaign
          • Instructions for sending a mobile push campaign with the Booster option
          • Reports & analytics
      • Outgoing
        • Outgoing list
        • Export list
      • Analytics and report
        • Push campaign report
        • Push campaign data storage
      • Common settings
        • Applications
        • Adding test device
      • Segmentation
    • RCS
      • RCS message types
      • What is a Brand Bot?
      • How to run RCS?
      • Tips for creating a campaign
      • Technical specifications of the RCS service
  • 🖥️API CHANNELS
    • E-mail API
      • Dashboard
      • E-mails report
      • Tag report
      • Domains report
      • Blacklist Report
      • Whitelist report
      • Settings
    • Mobile push API
      • Overwiev
      • Dashboard
      • Outgoing
        • Outgoing list
        • Export
    • SMS API
      • Overview
      • Dashboard
      • Incoming
        • Incoming list
        • Export
      • Outgoing
        • Outgoing list
        • Export
  • ⚙️TECHNICAL SUPPORT CENTER
    • Integrations
      • Integration with Salesforce
      • Integration with SalesManago
      • Integration with Synerise
      • Integration with IdoSell
    • Senders Authorization
      • How to Authorize Senders in MessageFlow?
        • Domains Authorization
        • Authorizing domains with web hosts
          • Authorizing a domain hosted at Nazwa.pl
          • Authorization of a domain hosted at Home.pl
          • Authorizing a domain hosted at cyber_Folks
          • Authorizing a domain hosted on Zenbox
          • Authorizing a domain hosted on OVHcloud
          • Authorizing a domain hosted on GoDaddy
        • SPF Record Configuration
    • System requirements
    • Technical assistance
    • API documentation
    • FAQ
  • Trust Center
    • Account Security
      • Password Management
      • Two-Factor Authentication (2FA)
      • IP Access Control
      • User & Role Management
    • Communication Channel Security
      • Email Communication Security
      • SMS Communication Security
      • RCS, Mobile Push & Viber Security
    • Data & Infrastructure Security
      • Our Commitment to Security
      • Data Center Security
      • Technical & Organisational Measures (TOMS)
      • Service Protection (WAF)
      • List of Procedures
    • Data Protection & Compliance
      • Legal Framework
      • Personal Data Processing at MessageFlow
      • Data Processing Agreement (DPA)
      • Document Templates
      • Sub-processors
    • Certifications & Audits
      • ISO Certifications
      • Security & Penetration Testing
      • Industry Standards & Affiliations
    • Abuse Prevention
      • MessageFlow Shield 360: Proactive Threat Protection
      • Recognising and Analysing Suspicious Messages (User Guidance)
      • Abuse Policy and Reporting
    • Security FAQ
Powered by GitBook
On this page
  • General Security & Compliance
  • Account Security
  • Platform & Sending Security
  1. Trust Center

Security FAQ

PreviousAbuse Policy and Reporting

Last updated 2 days ago

This section provides quick answers to common questions about security at MessageFlow. For more detailed information, please refer to the relevant sections of our Trust Center.

General Security & Compliance

What are MessageFlow's key security certifications?

We hold several internationally recognised certifications, including ISO 27001 for Information Security Management, ISO 27018 for Personal Data Protection in the Cloud, and ISO 22301 for Business Continuity Management. We are also a member of the Certified Senders Alliance (CSA). You can learn more in our Certifications & Audits section.

Where is my data physically stored?

All customer data is stored in secure, certified data centres located within the European Economic Area (EEA). We partner with industry-leading providers to ensure the highest level of physical security. For a full list of our infrastructure partners, see the Sub-processors section.

How does MessageFlow comply with GDPR?

We are fully committed to GDPR compliance. As your Data Processor, we process data only on your behalf. Our responsibilities are formalised in our Data Processing Agreement (DPA). You can find more details in the Data Protection & Compliance section.

Where can I find the legal terms of service?

The main legal document governing our relationship with our clients is the Framework Agreement on the Provision of Services by Electronic Means. The Privacy Policy and the Data Processing Agreement (DPA) are integral parts of this agreement. You can review the main agreement .

Can I sign a Data Processing Agreement (DPA)?

Yes. The DPA, an appendix to our Framework Agreement, is an integral part of our terms of service. To review or sign a copy, please .

Account Security

What is the single most effective way to secure my account?

Enabling Two-Factor Authentication (2FA) is the best step you can take. It provides a powerful second layer of security, even if your password is compromised.

Can I restrict who can log in to my account?
What should I do if I suspect my account has been compromised?

Platform & Sending Security

Is my data encrypted?

Yes. We use encryption to protect your data both in transit (using protocols like TLS) and at rest (while stored on our servers). You can find more details in the Data & Infrastructure Security and Email Communication Security sections.

Why is Sender Authorization (SPF, DKIM, DMARC) so important?

These protocols are essential for email deliverability and brand protection. They prove to receiving mail servers that you are a legitimate sender, which prevents your emails from being marked as spam and protects your brand from being impersonated by phishers. Learn more in our Senders Authorizationdocumentation.

How does MessageFlow protect against phishing and SMS fraud?
How do I report abuse or spam?

If you receive a suspicious message sent from our platform, please forward it to our support team for investigation. For general smishing, we recommend reporting it to a national body like CERT Polska. Find more details in the Abuse Policy and Reporting section.

Yes. We highly recommend using the IP Access Control feature to whitelist specific IP addresses for panel, and . You can also manage team access through User and role management.

Act immediately. First, . Second, review the list of active users in your account and check for any unrecognized activity. Finally, right away so we can help you investigate.

Our proprietary technology provides real-time protection against threats by analysing links and monitoring traffic in collaboration with security partners like CERT Polska and Google Safe Browse.

here
contact our support team
IP Authorization for SMTP servers
reset your password
contact our support team
Shield 360