Security & infrastructure

Serious about your data and your domains.

Your inboxes and prospect data are the core of your business. Tamly is built from day one to protect both.

Encryption in transit & at rest

Your data is encrypted on the wire and in storage, always.

Secure OAuth connections

Mailboxes connect via Google and Microsoft OAuth. We never store your passwords.

AWS infrastructure

Built on a reliable, scalable cloud foundation with isolation between workspaces.

Role-based access control

Decide who in your team can see, send, and manage each workspace.

Audit & activity logs

See who did what and when, across campaigns, inboxes, and contacts.

CASA Tier 2 in mind

Designed to meet Google's security bar for apps that access Gmail.

Our commitment

Built to the standards mailbox providers require

We're building Tamly with Google's CASA Tier 2 requirements for Gmail apps in mind. We don't claim certifications we haven't completed, but security is designed in, not bolted on.

No stored mailbox passwords
OAuth tokens only, revocable anytime
Data isolation per workspace
Your clients' data stays separated
Least-privilege access
Internal access is limited and logged
Responsible disclosure
A clear path to report any issue
Honest about compliance
We only claim what we've completed

Questions about security?

Our team is happy to walk through architecture, data handling, and access controls.

Contact the teamGet Early Access