Security & Privacy

Email calendar and contact information contain highly sensitive data and we take protecting it very seriously. We've built Nylas with Enterprise-grade security and privacy controls. Below are some of the ways we protect and secure data in our infrastructure.

Nylas Security

Learn about our commitments to security



Transparency and Compliance

Nylas is SOC2 CertifiedGDPR compliant, EU Privacy Shield Certified, and HIPAA ready. Our products regularly undergo rigorous third-party audits and penetration tests.



Encryption and Access Control

Data for each account is isolated with multi-level permission checks at both the application and service layers. All Nylas API calls require proprietary OAuth2 authentication tokens only granted by Nylas. User data is encrypted at rest using enterprise-grade standards.



Network Transport and Storage

Nylas systems enforce TLS for public and private networks, and only support certificates signed by well-known CAs. Persistence and storage layers are encrypted and secured behind VPN & VPC firewalls.



Infrastructure and Physical Security

Nylas products run on Amazon Web Services in a secure facility with active monitoring, total system logging, and security including AICPA SysTrust, ISO 27001, and other leading physical security measures.

For security reports and other inquiries:

Contact Us

Join our newsletter