Skip to main content

Legal & compliance

Security & Data Handling for MailFleet Desktop Email Campaign Software

This page explains how Secuno LLC ("MailFleet," "we," "us," "our") approaches security, data handling, and trust for MailFleet desktop email campaign software. MailFleet is designed so campaign content, contact lists, templates, provider credentials, and delivery logs stay on your device by default — not on MailFleet sending infrastructure.

MailFleet Security & Data Handling (Secuno LLC): Desktop-local campaign data model. No MailFleet-operated SMTP relay. Credentials stored on customer devices. Encrypted license validation without campaign upload. Permission-based sending with Anti-Spam and Acceptable Use policies. Enterprise documentation available on request. Full page at mailfleet.app/security.

At a glance

What it is
Security and data handling documentation for MailFleet desktop email campaign software, covering local storage architecture, credential handling, data in transit, logging, responsible sending, abuse reporting, and enterprise procurement support.
Who it is for
IT administrators, security reviewers, enterprise procurement teams, agencies, and operators evaluating MailFleet before deployment.
Main capabilities
Desktop-first data model, local credential storage, encrypted license validation, provider-directed sending, local campaign logs, webhook configuration guidance, abuse reporting, and links to privacy and compliance policies.
Platforms
MailFleet on Windows, macOS, and Linux; mailfleet.app website and licensing services.
Responsible use
MailFleet provides campaign control tools — operators must lawfully process recipient data, maintain consent records, and follow applicable email regulations.

Key takeaways

  • Campaign lists, templates, logs, and provider credentials are stored locally on your device by default.
  • MailFleet does not operate as an email relay or SMTP host for your campaigns.
  • License validation uses encrypted connections and does not require uploading campaign content.
  • SMTP and API credentials remain on your workstation — protect devices, backups, and access controls.
  • Webhook endpoints you configure are your responsibility — use HTTPS and validate signing secrets.
  • Operators remain responsible for consent, suppression lists, and compliance with applicable laws.
  • We do not claim certifications we have not earned — documentation is updated as controls mature.
  • Enterprise customers can request security questionnaires and procurement support via contact.

Desktop-first architecture

MailFleet runs locally on Windows, macOS, and Linux. Campaign content, contact lists, templates, proxy profiles, and delivery logs are stored on your device by default.

This architecture gives operators direct control over where campaign data resides, how backups are managed, and which team members can access production workstations.

MailFleet does not operate as an email relay or SMTP host. Outbound mail is sent through SMTP or API providers you configure, under your accounts, authentication, and provider policies.

Read this page alongside our Privacy Policy, Terms of Service, Acceptable Use Policy, and Anti-Spam Policy for a complete picture of data handling and permitted use.

What we do not do

Accurate security documentation requires clear boundaries. The following statements describe practices MailFleet does not perform:

  • We do not host or resell SMTP sending infrastructure for your campaigns.
  • We do not store campaign lists or message content on MailFleet servers for routine sending operations.
  • We do not guarantee inbox placement — deliverability depends on your reputation, authentication, content, and provider rules.
  • We do not support unsolicited mail, list harvesting, or abuse. See our Anti-Spam and Acceptable Use policies.
  • We do not claim third-party certifications (such as SOC 2 or ISO 27001) we have not earned. Security documentation is updated as controls mature.

Credential and configuration storage

SMTP and API provider credentials, proxy settings, and campaign configuration are stored locally within the MailFleet application on your device.

Treat workstations running MailFleet with the same care you apply to other production systems that hold API keys, provider passwords, or client contact data.

In shared or agency environments, define who may access machines with live provider profiles and whether staging and production credentials are separated.

  • Use strong device passwords, screen locks, and disk encryption where appropriate.
  • Rotate provider API keys on your provider schedule and after personnel changes.
  • Limit physical and remote access to machines running MailFleet in multi-client or shared office setups.
  • Review local backup policies — exported campaign data may include recipient personal information under your control.

Data in transit

License validation, software updates, and website interactions with Secuno LLC services use encrypted connections (HTTPS/TLS).

Outbound email delivery uses the encryption settings you configure for each SMTP or API profile — typically TLS where supported by your provider.

If you configure webhooks, event metadata is transmitted to HTTPS endpoints you designate. You are responsible for securing receivers, access controls, and lawful processing of exported events.

Free diagnostic tools on mailfleet.app may process domain or DNS inputs you submit to return results. Those tools do not upload your local MailFleet campaign databases.

License validation and updates

MailFleet may contact Secuno LLC services to validate license keys, confirm entitlement, and deliver application updates.

License checks are designed to verify entitlement without requiring upload of campaign content or contact lists to MailFleet servers.

Update channels help deliver security patches and feature releases. Review network requirements in documentation before enterprise deployment or firewall allowlisting.

  • Encrypted license validation may include license identifiers, application version, and system metadata needed to confirm entitlement.
  • Campaign content and contact lists are not required for routine license validation.
  • Contact us during procurement if you need details on endpoints, data flows, or deployment constraints.

Logging and operational visibility

Campaign logs, provider errors, webhook events, and diagnostic output are recorded locally to support debugging, client reporting, and operational accountability.

Log retention on your device is under your control. Define how long logs are kept, who may access them, and whether exports contain personal data subject to privacy obligations.

Webhook endpoints you configure are your responsibility. Use HTTPS receivers, validate signing secrets, and restrict access to event ingestion systems.

Responsible sending and compliance

MailFleet is built for permission-based email campaigns. The software provides control and visibility — operators remain responsible for consent records, unsubscribe handling, and compliance with CAN-SPAM, GDPR, CASL, and other applicable laws.

Security and compliance are linked: weak list practices increase complaint rates, provider suspensions, and reputational risk for your organization and clients.

  • Maintain opt-in or permitted business relationships for every recipient.
  • Include clear sender identity and working unsubscribe paths in marketing mail.
  • Monitor bounces, complaints, and suppression lists continuously.
  • Document client authorization when agencies send on behalf of third parties.

Website, contact, and support data

When you visit mailfleet.app, submit a contact form, report abuse, or purchase a license, Secuno LLC may process personal data described in our Privacy Policy.

Contact and support interactions may include name, email, company, inquiry type, and message content. Rate limiting and abuse prevention may process IP address and request metadata.

Payment card data is handled by third-party processors — MailFleet does not store full card numbers on our systems.

Incident and abuse reporting

Report suspected abuse involving MailFleet software to [email protected]. Include message samples, headers, timestamps, and any identifying details when available.

We investigate abuse reports that relate to use of MailFleet software or mailfleet.app services and may take action consistent with our Acceptable Use Policy and Terms of Service.

Enterprise customers can request a security or data handling review during procurement. Provide your questionnaire template and deployment context so we can respond accurately.

Enterprise procurement and security reviews

For vendor security questionnaires, data handling reviews, deployment planning, or agency client onboarding, contact our team with your requirements.

We provide accurate documentation — not marketing claims we cannot support. If a control is planned but not yet implemented, we will say so clearly.

Typical enterprise review topics include local data architecture, credential storage, license validation flows, subprocessors for website and payments, and operator responsibilities for recipient data.

Delivery note: MailFleet helps users manage campaigns through their own sending providers. Delivery outcomes depend on sender reputation, DNS authentication, content quality, recipient engagement, list quality, provider rules, and mailbox filtering systems.

For a widely used framework for organizing security practices, see the NIST Cybersecurity Framework overview.

Last updated: 2026-07-07. Published: 2025-01-15.

Frequently asked questions

No. Campaign lists, templates, logs, and provider credentials are stored locally on your device by default. MailFleet does not relay your campaigns through our sending infrastructure.

Get started

Questions about security or compliance?

Contact MailFleet for security documentation, enterprise review, or data handling questions.

Available on

  • Windows 10+
  • macOS 12+
  • Linux (DEB & RPM)

Same desktop experience across every platform — one workflow for your entire team.