DEVECTUSSenderDeckBack to SenderDeck

// Security

Small attack surface. Strong user control.

SenderDeck is designed to minimise retained data and keep sensitive email actions deliberate.

Last updated 4 August 2026

SenderDeck resourcesPrivacyTermsSecuritySupport

Security principles

  • Least privilege: delegated OAuth permissions are limited to the email functions SenderDeck provides.
  • On-demand access: mailboxes are not synchronised or indexed into a separate message database.
  • Encrypted credentials: OAuth tokens are encrypted before storage and are separated by authenticated user.
  • Per-user MCP authorization: Codex connections use OAuth 2.1 authorization code flow with PKCE, short-lived access tokens and rotating refresh tokens.
  • Provider-hosted drafts: drafts remain with Google or Microsoft.
  • Deliberate sending: sending requires confirmation of the exact sender, recipients, subject and attachment list.
  • Attachment controls: configurable type and size limits block high-risk or oversized attachments.
  • Minimal retention: message bodies and attachment contents are processed transiently for requested operations.

Account control

Users can review connected identities, rename local routing labels and disconnect accounts. Access can also be revoked through Google or Microsoft account consent settings. Disconnecting removes the SenderDeck connection without deleting provider-hosted email.

Service boundaries

SenderDeck does not perform automatic or scheduled sending, background monitoring, bulk campaigns, calendar operations or shared mailbox access. These exclusions reduce both privilege and misuse risk.

Responsible disclosure

If you believe you have found a security issue, email support@devectus.com.au with “SenderDeck security report” in the subject. Include a clear description, affected URL or feature, reproducible steps and the potential impact. Do not access other users’ data, disrupt service, perform social engineering or publish sensitive details before we have had a reasonable opportunity to investigate.

Privacy incidents

Privacy concerns or suspected exposure of personal information should be reported to privacy@devectus.com.au.

Designed & built byDEVECTUS

DEVECTUS Pty Ltd · Melbourne, Australia

PrivacyTermsSecuritySupport