PricingLogin
Get Started Free

Email Verification

Free email checker

Free Email Checker

Verify any address in 2 seconds

Email verification

Email Verification

Full product overview

Email verification API documentation

API Documentation

Real-time + bulk endpoints, code samples

Email verification MCP server

MCP Server

For AI agents: Claude, Cursor

Verify email on website with FoxGuard widget

FoxGuard Widget

Embed live validation on any form

Email Finder

Email finder

Email Finder

Find anyone's verified email by name + domain

LinkedIn email finder

LinkedIn Email Finder

From any LinkedIn profile URL

Domain email extractor

Domain Email Extractor

Pull every email from a domain

Bulk email finder

Bulk Email Finder

Upload a CSV of names

Email finder API

Email Finder API

Programmatic email discovery

1:1 Consulting

Deliverability and cold outreach, tuned to your stack.

Book a 30-min audit

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Refund Policy
  • Subprocessors
  • Trademark Policy
  • EU & Swiss Privacy Policy
  • California Privacy Rights
  • GDPR Compliance
  • Security Policy
  • Research Policy

Product

  • Zero Bounce Guarantee
  • What We Do

Navigation

  • Site Map

Security Policy

Last updated: March 27, 2026

Our Security Commitment

Security is foundational to Verifox (verifox.ai). As an email intelligence platform handling B2B contact data and API keys at scale, we recognise that our security posture directly impacts our customers' security. We maintain a formal information security management programme aligned with industry best practices.

To report a security vulnerability, contact us immediately at [email protected]. For non-urgent security inquiries, email [email protected]. We do not accept vulnerability reports via social media or public issue trackers.

SOC 2 Type II

Verifox undergoes an annual SOC 2 Type II audit conducted by an AICPA-accredited independent auditor. Our audit covers the Trust Services Criteria for Security, Availability, and Confidentiality. The most recent SOC 2 Type II report is available to enterprise customers under NDA upon request at [email protected].

SOC 2 compliance means that our controls have been independently tested and verified over an extended observation period — not just a point-in-time snapshot. The audit covers access controls, change management, risk assessment, incident response, and vendor management.

Encryption

We apply encryption at multiple layers:

  • Data in transit: All communications between your browser/app and our servers are encrypted using TLS 1.2 or TLS 1.3. We do not support SSL or TLS 1.0/1.1. Our TLS certificate chain uses SHA-256 or stronger.
  • Data at rest: Databases and file storage are encrypted using AES-256. AWS RDS instances use AWS-managed encryption keys with annual rotation.
  • API keys: API keys are stored as salted hashes. We display an API key only once, at the time of generation. We cannot recover a lost key — you must rotate it.
  • Passwords: User passwords are hashed using bcrypt with a cost factor of at least 12. We do not store plaintext passwords.

Access Control

We apply the principle of least privilege across our systems:

  • Production system access is restricted to a small group of authorised engineers via VPN and multi-factor authentication (MFA).
  • Database access from application servers uses read/write-segregated roles with minimum required permissions.
  • Customer data is logically isolated by organisation ID — no customer can access another customer's data.
  • Administrative access to customer accounts is logged and audited. Support staff access data only when investigating authorised support tickets.
  • Access is revoked immediately upon employee offboarding.

Penetration Testing and Vulnerability Management

We conduct security assessments on a regular basis:

  • Annual external penetration test: Conducted by an independent third-party security firm. Scope includes the web application, API, and network perimeter.
  • Continuous vulnerability scanning: Automated scanning of our codebase (SAST), dependencies (SCA), and infrastructure using tools including Snyk and AWS Inspector.
  • Patch management: Critical and high-severity vulnerabilities in dependencies are patched within 72 hours of identification. Medium-severity within 14 days.

Responsible Disclosure (Bug Bounty)

We welcome responsible disclosure of security vulnerabilities. If you discover a potential security issue in our platform, please report it to [email protected] before public disclosure, and allow us a reasonable time (typically 90 days) to investigate and remediate.

In your report, please include: (a) a description of the vulnerability; (b) steps to reproduce; (c) the potential impact; and (d) any proof-of-concept code. We will acknowledge your report within 2 business days and keep you informed of our progress.

We do not pursue legal action against researchers who follow these guidelines. We offer recognition (and in some cases monetary rewards) for impactful, responsibly disclosed findings, at our discretion.

Incident Response

We maintain a documented incident response plan that covers detection, containment, eradication, recovery, and post-incident review. In the event of a confirmed data breach affecting your personal data or Customer Data:

  • We will notify affected customers within 24 hours of confirming the breach.
  • We will notify relevant supervisory authorities within 72 hours as required by GDPR Art. 33.
  • We will provide a full incident report within 14 days, including root cause analysis and remediation steps.

Our on-call security team is available 24/7 for critical incident response. For security emergencies, email [email protected] with "URGENT" in the subject line.

Physical and Operational Security

Our infrastructure is hosted in AWS data centres that hold ISO 27001, SOC 1, SOC 2, and SOC 3 certifications. AWS data centres include physical security controls such as 24/7 security personnel, multi-factor access control, CCTV, and environmental controls (fire suppression, power redundancy, cooling).

Verifox employees working with customer data are subject to background checks, security training at onboarding, and annual security awareness training. Remote working policies include requirements for encrypted devices, VPN usage, and screen locks.

On this page

  • Our Security Commitment
  • SOC 2 Type II
  • Encryption
  • Access Control
  • Penetration Testing and Vulnerability Management
  • Responsible Disclosure (Bug Bounty)
  • Incident Response
  • Physical and Operational Security

Questions?

Contact our legal team at [email protected]

Trust & compliance

Enterprise-grade security and scale

Every layer of the stack carries a third-party attestation, so you can ship into regulated industries without rebuilding your compliance posture.

  • Claymation Japanese hanko seal in jade-green clay with a twisted shimenawa rope rim, the words SOC 2 TYPE II embossed in cream clay on its face.

    SOC 2 Type II

    Independently audited to the SOC 2 Type II standard.

  • Claymation Japanese hanko seal in cobalt-blue clay with a twisted shimenawa rope rim, the word GDPR embossed in cream clay on its face.

    GDPR

    Built for the EU with full GDPR data-subject rights.

  • Claymation Japanese hanko seal in rose-pink clay with a twisted shimenawa rope rim, the word CCPA embossed in cream clay on its face.

    CCPA

    California opt-out, do-not-sell, plus DSAR handling.

  • Claymation Japanese hanko seal in terracotta clay with a twisted shimenawa rope rim, the text ISO 27001 embossed in cream clay on its face.

    ISO 27001

    Information security held to the ISO 27001 standard.

  • Claymation Japanese hanko seal in lilac-purple clay with a twisted shimenawa rope rim, the text ISO 42001 embossed in cream clay on its face.

    ISO 42001

    AI governance aligned to the new ISO 42001 standard.

Stop bouncing. Start verifying.

1,000 free credits on signup. 2,500 with a work email.No card, no monthly minimum, and credits that never expire.

Get Started Free

Go to market with verified data, and the engine to act on it.

Get Started FreeExplore the API

Verified data for teams that ship.

Product

  • Email Verification API
  • Email Finder API
  • Email Scoring
  • Email Warmup
  • MCP Server
  • Pricing

Free tools

  • Free Email Checker
  • Free Email Validator
  • Email Verifier
  • Email Blacklist Check
  • MX Lookup
  • SMTP Test

Email finder

  • Email Finder
  • AI Email Finder
  • Bulk Email Finder
  • LinkedIn Email Finder
  • Email Lookup
  • Domain Email Extractor

Compare

  • vs ZeroBounce
  • vs NeverBounce
  • vs Hunter
  • vs Bouncer
  • vs Kickbox
  • vs Emailable
  • vs Clearout

Developers

  • API Documentation
  • MCP Server
  • SDKs
  • Status Page
  • Blog
  • Glossary

Company

  • What We Do
  • Security
  • Privacy Policy
  • Terms of Service
  • Contact
  • Site Map
Built in San Francisco© 2026 All rights reserved. Verifox AI