Security & compliance

Privacy isn't a setting. It's the architecture.

Evercontact reads the most sensitive system your company owns, your email. We've spent years earning the right to. We never train models on your data, never resell contacts, and encrypt everything end to end.

S2
SOC 2 Type II
Independently audited
CA
Google CASA
Tier 2 security assessment
GD
GDPR
EU residency available
Our commitments

Three promises we put in writing.

Promise 01

We never train on your data.

Your email is processed to extract contacts and nothing else. It is never used to train, fine‑tune, or improve any model. We use synthetic and licensed corpora for that, never your inbox.

Promise 02

We never sell your contacts.

Evercontact has no data‑broker business and no shared enrichment pool fed by customer mail. The contacts we extract are yours alone. Our only revenue is the software you pay for.

Promise 03

You stay in control.

Access is granted by revocable OAuth and can be withdrawn instantly. You can export or delete your data at any time, and we honor every GDPR data‑subject request within statutory windows.

How data flows

Encrypted in transit. Encrypted at rest.

Mail moves over TLS 1.3, is processed in isolated per‑tenant environments, and contact records are stored under AES‑256 encryption. Every action writes to an immutable audit log with configurable retention.

TLSIn transit
TLS 1.3 everywhere, HSTS enforced, modern cipher suites only.
AESAt rest
AES‑256 encryption for all stored records and backups.
ISOIsolation
Per‑tenant logical isolation; least‑privilege internal access.
LOGAudit log
Immutable, exportable, with configurable 7‑year retention.
Data flow Inbox Google / Microsoft TLS 1.3 Evercontact AI isolated · no training CRM Address book Warehouse audit_log → immutable · AES‑256 · retention: 7y
Compliance reference

Controls, at a glance.

AreaStandardWhat it covers
Service controlsSOC 2 Type IISecurity, availability, and confidentiality, audited annually by an independent firm.
App & API securityGoogle CASACloud Application Security Assessment (Tier 2) validating how we handle Google Workspace data and OAuth scopes.
Data protectionGDPRLawful basis, DPA, sub‑processor transparency, and data‑subject rights to access, delete, and port data.
IdentitySSO + SCIMSAML single sign‑on and automated provisioning via Okta, Azure AD, and Google.
Resilience99.99% SLARedundant infrastructure, monitored uptime, and a public status page.
Your data rights

Access, export, or erase, anytime.

EXExport
Download all of your contact data in a portable format whenever you want, no support ticket required.
DELDelete
Request full erasure and we remove your data within statutory windows, confirming in writing when complete.
REVRevoke
Withdraw OAuth access in one click from your provider's console; processing stops immediately.
SUBSub‑processors
We publish our sub‑processor list and notify customers in advance of any material change.

Security you can start using today.

Privacy-first architecture, no training on your data, and encryption end to end — built in from day one. Connect your inbox and see it for yourself, free for 14 days.