Security & Compliance

How MySecureSend protects your data, and where it lives.

Where your data lives

Database & files metadata

Supabase, Sydney (AWS ap-southeast-2)

Application hosting

Vercel, Sydney (syd1)

Encryption service

Google Cloud Run, australia-southeast1 (Sydney)

What’s encrypted, and where

Files are encrypted with AES-256 on our Sydney servers before the email is sent. PDF files are encrypted natively. Office documents use msoffcrypto. All other file types are encrypted into an AES-256 protected .zip via pyzipper.

OAuth2 tokens (used to send email on your behalf) are encrypted with AES-256 before storage. All database connections use TLS.

Zero file retention

Files exist on our systems only for the seconds it takes to encrypt and send them. Once the email is sent, the file is discarded. We do not store file contents at any point, and cannot retrieve or reproduce a file after it has been sent.

Retention periods

Data typeRetention
Account dataDuration of account + 90 days after deletion
Audit log (send_logs)7 years, to meet compliance obligations
OAuth2 tokensUntil you disconnect the account or delete it
FilesNot retained - discarded immediately after sending

OAuth scopes we request, and why

We connect to your Gmail or Outlook 365 account using send-only permissions:

Gmail: gmail.send - lets us send email as you. We cannot read your inbox, search your mail, or access anything beyond sending the message you initiate.

Outlook 365: Mail.Send - same principle. Send-only, no inbox read access.

Subprocessors

We use the following service providers to deliver MySecureSend. Each is used strictly for the purpose below, and none receive your file contents.

SubprocessorPurposeLocation
SupabaseDatabase & authenticationSydney (ap-southeast-2)
VercelApplication hostingSydney (syd1)
Google Cloud RunFile encryption processingSydney (australia-southeast1)
TwilioSMS delivery (password notifications)-
ResendTransactional email delivery-
GoogleOAuth2 - sending email on your behalf only-
MicrosoftOAuth2 - sending email on your behalf only-

This list is also referenced from our Privacy Policy and our Data Processing Agreement.

Data Processing Agreement

If your practice needs a signed Data Processing Agreement in place, email us at support@mysecuresend.com.au and we’ll send one across for you to countersign.

Reporting a security issue

If you’ve found a security vulnerability, email us at support@mysecuresend.com.au. We’ll acknowledge your report and investigate promptly. Please don’t publicly disclose an issue before we’ve had a chance to address it.

Questions

For anything else, contact support@mysecuresend.com.au.