Trust & Safety

Security at NevTan Mail

An overview of how we protect your mail, your account, and your team's data.

NevTan Mail is built for businesses that trust us with their email, contacts, and calendar. This page describes the practical measures in place around mail transport, spam and phishing defenses, and account access. For how we collect, use, and retain your data, see our Privacy Policy.


1. Encrypted Mail Transport

Mail moving in and out of NevTan Mail is encrypted in transit:

  • Outbound email is sent over SMTP with STARTTLS, so messages are encrypted between our servers and the receiving mail server.
  • When you import or sync mail from another provider, we connect over IMAPS (implicit TLS on port 993) rather than plain IMAP.
  • The NevTan Mail web app itself is served over HTTPS, so traffic between your browser and our servers is encrypted.

2. Spam & Phishing Protection

Incoming mail is checked against a sender and domain blocklist before it reaches your inbox. Messages from a sender or domain flagged as spam are routed to your Spam folder instead of your Inbox, and mail already filed as spam or junk by an imported provider is preserved as spam rather than mixed into your Inbox on import.

As with any email service, we recommend treating unexpected attachments, links, or requests for credentials with caution, even from senders that appear to be known contacts.

3. Account & Access Security

  • Passwords are never stored in plain text — they are hashed with bcrypt before being saved.
  • Sign-in sessions use time-limited JSON Web Tokens, so a session cannot be replayed indefinitely.
  • Password reset links expire shortly after they're issued, so an old reset email can't be reused later.
  • Role-based access controls separate standard mailbox users, domain Admins, and NevTan Super Admins — each role only reaches the screens and data appropriate to it.

4. Payment Security

Subscription payments are processed by Stripe, a PCI-compliant payment processor. Your card details are entered and stored by Stripe directly — NevTan never receives or stores your full card number.

5. Reporting a Vulnerability

If you discover a security vulnerability in NevTan Mail, please report it responsibly to support@nevtan.com with a description of the issue. We investigate all reports and respond within 5 business days. Please do not publicly disclose vulnerabilities before we've had the opportunity to investigate and address them.

6. Questions

For questions about security practices not covered here, contact support@nevtan.com.