Skip to content

Security

Your list is sensitive. We treat it that way.

day3 holds your subscribers' personal data, so security isn't a page we bolt on — it's how the product is built. Here's exactly what we do, stated plainly.

EU-only data residency

day3 runs entirely in the European Union. Your data and your subscribers' data are stored and processed in the EU — they don't leave it.

Encrypted in transit and at rest

Every connection is served over TLS. Data at rest is encrypted by our infrastructure providers using industry-standard ciphers.

Audited infrastructure

We build on Vercel and Supabase, both of which maintain SOC 2 Type II reports. The platform underneath day3 is independently audited.

Least-privilege access

Access to production data is restricted to what's needed to run the service, protected by strong authentication, and kept to a minimum.

Backups & recovery

Your data sits in a managed Postgres database with automated backups and point-in-time recovery handled by Supabase.

Sensible sending defaults

Authenticated domains, one-click unsubscribe, automatic bounce and complaint handling, and per-sender suppression lists by default.

Where we stand

Honest about compliance.

We won't put a badge on this page that we haven't earned. day3 is not SOC 2 audited today. What is true: day3 runs on infrastructure that holds SOC 2 Type II reports — Vercel and Supabase — so the platform beneath us is independently audited, and a formal day3 audit is on the roadmap as we grow.

On data protection we're on firmer ground. day3 is an EU company processing data in the EU. We act as your GDPR data processor, offer a Data Processing Agreement, and publish every sub-processor that can touch your data.

Sub-processors

The short list of who can touch your data.

Every vendor below is EU-region. We keep the list deliberately small.

  • VercelApplication hosting, edge network and content delivery · European Union
  • SupabaseDatabase, authentication and file storage · European Union
  • Amazon SESOutbound email delivery · European Union (Stockholm)

The complete, current list lives on the sub-processors page.

Responsible disclosure

Found something? Tell us.

If you believe you've found a security vulnerability in day3, email hello@day3.app with the details and steps to reproduce. We'll acknowledge your report and keep you posted on the fix.

Act in good faith — don't access or modify data that isn't yours, and give us reasonable time to respond — and we won't pursue or support legal action against you.

Common questions

Where is day3 hosted?
Entirely in the European Union. day3 runs on Vercel (hosting and delivery) and Supabase (database, authentication and storage), both in EU regions. Your data does not leave the EU.
Is day3 SOC 2 certified?
Not yet. day3 is a young product and we won't claim a certification we don't hold. What we can say honestly: day3 is built on SOC 2 Type II–audited infrastructure (Vercel and Supabase), and a formal day3 audit is on our roadmap as we grow.
Is day3 GDPR compliant?
Yes. day3 is an EU company that processes data in the EU. We act as your data processor for the subscribers you import, offer a Data Processing Agreement, and publish the full list of sub-processors we use.
Who owns the subscriber data I import?
You do. day3 processes your contacts solely to deliver your campaigns and report on them. We never sell, rent, or use them to market anything of our own.
How do I report a security issue?
Email hello@day3.app with the details. We welcome responsible disclosure, will acknowledge your report, and won't pursue researchers who act in good faith.

Questions about security or data?

Email a human who can actually answer them.