Enterprise-grade security and privacy controls have always been at the heart of Nylas. Here are some of the ways we protect and secure data in our infrastructure.
Nylas is Safe Harbor Compliant for both US-EU and US-Swiss standards, and is PCI and HIPAA ready. Our products regularly undergo rigorous 3rd-party audits and penetration tests.
Data for each account is isolated with multi-level permission checks at both the application and service layers. All Nylas API calls require proprietary OAuth2 authentication tokens only granted by Nylas. User data is encrypted at rest using military-grade standards.
Nylas systems enforce TLS for public and private networks, and only support certificates signed by well-known CAs. Persistence and storage layers are encrypted and secured behind VPN & VPC firewalls.
Nylas products run on Amazon Web Services in a secure facility with active monitoring, total system logging, and security including AICPA SysTrust, ISO 27001, and other leading physical security measures.
For bug disclosure and other inquries:
Contact our Security Team