Security
Your account
- Passwords are stored as bcrypt hashes (cost 12). We cannot read them.
- Two-factor authentication is available on every account; we recommend turning it on.
- Sessions are server-side with reuse detection, so a stolen cookie invalidates itself on use.
- Google sign-in verifies the provider-attested email address.
Your API keys
Keys are 32-byte random values with the eva_ prefix, stored only as bcrypt hashes. A key is shown once at creation and never again. Revoking a key takes effect immediately.
Your lists
You are the controller; we are the processor. Addresses you submit are used only to produce your verification results. We never sell, share, or mail them. Verification traffic to foreign mail servers presents our own dedicated probe identities and contains nothing of yours beyond the address being checked.
Transport and infrastructure
HTTPS everywhere, HSTS, automatic certificate renewal. The API runs behind Cloudflare with the origin restricted to Cloudflare address space. Production data lives in an encrypted-at-rest database with nightly encrypted off-site backups.
Responsible disclosure
Found something? Mail abuse@verifications.email. We read every report and answer within two business days.