Security & Trust

How Innbocks Protects Your Customers' Mail

Mailbox operators handle government IDs, notarized forms, and other people's mail. This page lists what the platform does to protect that data. Every item here describes behavior that is in the product today.

What the Platform Does

Accounts and access

  • Passwords are stored only as bcrypt hashes, never in plain text.
  • Vendors and staff can turn on multi-factor authentication with an authenticator app (TOTP) and receive recovery codes. A store owner can require MFA for every staff account.
  • Sign-up, password reset, and multi-factor code entry are rate-limited against brute force.
  • Staff accounts are separate from the owner account, and the owner decides whether each staff member can change customer plans and billing.
  • Vendors can view the portal as one of their customers in a read-only mode. While that mode is active the app blocks every write, so nothing can be changed on the customer's behalf.

Documents and mail scans

  • Mail scans, ID documents, Form 1583s, and notary certificates live in private storage. There is no public bucket and no public CDN path.
  • Every file read is served through a short-lived signed link minted for that request, after the requester's right to the record is checked.
  • Scans and IDs are never attached to email as public links. Links in email are signed and expire.

Mail handling records

  • Every mail action (received, opened, scanned, forwarded, shredded, discarded, delivered) writes an event to a hash-chained chain of custody. Each event carries a hash of its own data and the previous event's hash, so any edit after the fact is detectable.
  • Quarterly USPS certifications are recorded with an immutable snapshot of the compliance evidence at the moment of certification. Later finalizations are appended, never rewritten.
  • Customer acceptances of your terms of service and privacy policy are stored with the policy version and a frozen copy of the text they agreed to.

Payments

  • All customer payments run through Stripe Connect. Card data never touches Innbocks servers.
  • Charges are created on your own connected Stripe account, so payouts go to you, not through us.
  • Incoming Stripe events are signature-verified, and each event is reserved and processed once, even if Stripe retries it.

Integrations

  • Partner API keys are scoped to the permissions you choose and stored as SHA-256 hashes. The raw key is shown once and cannot be recovered from our database.
  • Every key has its own rate limit, and requests over the limit are rejected before any work is done.
  • Outbound webhooks are signed with an HMAC-SHA256 signature so your systems can verify each delivery came from Innbocks.

Your data is yours

  • Export your customer records and mail history any time.
  • When you leave, the store owner can request a full export: customers, mail history, and every stored document, packaged as CSV, JSON, and zip archives you download directly.
  • Customer records are kept for the USPS retention period after a customer leaves (Form 1583 must be retained for six months after termination), then purged automatically.

Monitoring

  • Production errors are reported to an error monitoring service with session replay switched off and default PII collection disabled, so mail scans and Form 1583 screens are never recorded.
  • Product analytics run only on the Innbocks marketing site and only with cookie consent. They are switched off on branded store domains, so customer mail and portal activity is never sent to an analytics provider.

Day-to-Day Practices

  • All traffic is encrypted in transit with TLS.
  • Each vendor's data is scoped to their own store, so customers, mail, and documents are isolated per tenant.
  • Scheduled jobs that touch customer data (retention purges, billing reconciliation, compliance reminders) require a server-side secret and refuse unauthenticated calls.
  • USPS Form 1583, e-notarization, and CRD workflows are built in. See our compliance center for the full picture.

Compliance is its own discipline. Read about our USPS 1583 and CRD compliance center.

What We Don't Claim

Innbocks does not hold a SOC 2 report today, and a formal third-party security audit is not complete. We would rather say that plainly than imply otherwise. If your organization needs a completed security questionnaire before signing, contact us and we will fill one out with specifics about the controls described on this page.

Questions?

Ask about any control on this page, request a security questionnaire, or report a concern.

Contact Us