惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

GbyAI
GbyAI
人人都是产品经理
人人都是产品经理
Hugging Face - Blog
Hugging Face - Blog
罗磊的独立博客
博客园 - 【当耐特】
D
Docker
Y
Y Combinator Blog
L
LangChain Blog
博客园 - 三生石上(FineUI控件)
I
InfoQ
阮一峰的网络日志
阮一峰的网络日志
F
Fortinet All Blogs
J
Java Code Geeks
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
V
V2EX
B
Blog
The GitHub Blog
The GitHub Blog
腾讯CDC
MongoDB | Blog
MongoDB | Blog
博客园 - Franky
爱范儿
爱范儿
A
About on SuperTechFans
量子位
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC

Buttondown's blog

Email could have been X.400 times better The physicists who convinced Fermilab to send Brazil's emails Better in-app previews Analytics 3.0 Subscriber ID variables Comments! Send latest premium action Automation filtering Free API subscribers Surveys in automations Reply to replies Labels for RSS feeds How Jeremy Singer-Vine curates curious datasets for readers 2023 (and what's next) Email vs web content Sort by engagement Better gift subscriptions How Andy Dehnart built a career reviewing television New email template Email-based automations Opt-in reply tracking Automatic alt text More social network integrations Sort by metadata Overlarge image warnings Automation tag actions Pause emails mid-flight Search tags and automations Gift via automations Subscriber-driving emails
Security
Buttondown Team · 2025-02-01 · via Buttondown's blog

We value your data and are committed to keeping it safe and secure. This document outlines some of the ways handle your data with care in transit and at rest.

Organizational Security

We are a small (but mighty!) team. Here are some of the best practices we’ve adopted:

  • Access to servers, source code, and third-party tools is limited to core team members.
  • We use strong, randomly-generated passwords stored in a password manager (1Password).
  • Employees and contractors are given the lowest level of access that allows them to get their work done. This rarely includes access to production systems or data.
  • We use automatic security vulnerability detection tools to alert us when our dependencies have known security issues. We are aggressive about applying patches and deploying quickly.
  • We don’t copy production data to external devices (like personal laptops).

Encryption

All data is encrypted in transit and at rest.

When a user connects a third-party service (like Google or Twitter) to Buttondown, we only receive a token that allows us to access their data. We do not store any of that data, and we encrypt it before storing it in our database.

Infrastructure

Our application is hosted in two separate environments: Vercel and Heroku. Our database is hosted on PlanetScale in the us-west-2 AWS region.

Data Retention

We only retain data for as long as it is necessary to provide the service. We do not sell or share your data with third parties.

Subprocessors

For a full list of the third-party services we use to process data, see our subprocessors page.

FAQ

Is Buttondown GDPR-compliant?

Yup; you can read more about it here.

Is Buttondown SOC 2-certified?

No. While we'd like to reach these certifications, we don't have a timeline or plan to do so. Our core infrastructure providers are SOC 2-certified, but we're not.

How do I report a security issue?

Please email us at support@buttondown.com.