This page provides an overview of the security practices put in place to run Missive. For any question, please contact us at security@missiveapp.com.
Our security.txt can be found here.
External audit
SOC 2
Missive is compliant with the SOC 2 standard, which is a widely recognized auditing standard for service providers. The SOC 2 compliance ensures that we have implemented rigorous security policies and procedures (penetration testing, vulnerability scanning, etc.) to safeguard customer data. We are audited by a third-party CPA based in California, USA.
Our SOC 2 report is available upon request. Please contact us at security@missiveapp.com to obtain a copy.
Google OAuth API Verification
To assess the quality of our security practices, we successfully went through the security audit required by Google as part of their OAuth API Verification.
This security assessment is mandatory for any service that connects to Gmail / Google Workspace (formerly known as G Suite) accounts and stores data on their servers or cloud storage. It is an extensive process put in place by Google to ensure providers such as Missive can guarantee a high level of security and privacy when processing and storing user-provided data. You can read more about this security assessment on Google’s FAQ here.
The letter of assessment provided by the Google-mandated external auditor can be obtained by emailing us at security@missiveapp.com.
Infrastructure
Our service is built on Amazon Web Services and Heroku. These providers offer strong security measures and are compliant with most certifications. Feel free to read more about the security practices of each:
Data encryption
Encryption in transit
All connections between Missive apps and our servers are encrypted using the Transport Layer Security standard (TLS). This also applies to connections between our servers and third-party providers such as Gmail, Office 365, Twilio, Facebook, Asana, Pipedrive, Trello, and others.
Here are links to SSL quality reports for our main application domains:
Encryption at rest
All data stored in our database and cloud storage is encrypted at rest.
Responsible disclosure
We encourage security researchers to report vulnerabilities in accordance with our vulnerability disclosure program.
GDPR
Missive is compliant with the General Data Protection Regulation (GDPR). See our dedicated GDPR page for more information.
Payment information
All payments made through our services are processed by Stripe which is certified as a PCI Level 1 Service Provider. We do not collect or store payment information in our infrastructure.