🚀 Gran noticia: Programa de Clientes Fundadores — Obtén de por vida 50 % de descuento en todos los planes

Outbird

Security at Outbird

Last updated: Sep 2026

Built to help you protect your data and keep your outreach running.

Outbird is designed to help businesses manage outbound email campaigns, prospect data, and connected services with appropriate security controls.

We take the security of customer information seriously and work to protect it through access controls, secure infrastructure, and responsible data handling.

1. Protecting Your Data

Outbird uses technical and organizational measures designed to protect information against unauthorized access, loss, misuse, alteration, or disclosure.

Our security practices are designed around the types of information we process, including account information, campaign data, prospect information, and data from connected services.

We continually review and improve our security practices as our platform evolves.

2. Data Encryption

We use encryption and other technical safeguards to help protect information during transmission and, where supported by our service providers, while stored.

Our safeguards may include:

  • Encryption in transit: Information transmitted between your browser, Outbird, and our service providers may be protected using HTTPS and Transport Layer Security (TLS).
  • Encryption at rest: Data stored by Outbird or its infrastructure providers may be protected using encryption at rest, where supported by the relevant provider and service.
  • Secure service communication: We take reasonable steps to protect communication between application components and connected services.
  • Protected storage: We apply appropriate safeguards to protect sensitive information stored within our systems.

We do not claim that any system is completely secure. Security measures may vary depending on the service, infrastructure provider, integration, or type of information involved. We continually review and improve our safeguards to reduce security risks.

3. Access Controls

Access to customer information is limited to authorized personnel and systems that need it for legitimate business, support, security, or operational purposes.

Depending on the system and service involved, our access-control practices may include:

  • Role-based access permissions
  • Authentication requirements
  • Restricted access to administrative systems
  • Periodic review of access permissions
  • Protection of credentials, API keys, and other secrets
  • Removal or adjustment of access when it is no longer required

We aim to follow the principle of least privilege, meaning access is limited to what is reasonably necessary for the relevant task. Access controls may vary depending on the infrastructure provider, connected service, and type of information involved.

4. Account Security

We take reasonable steps to help protect Outbird accounts and reduce the risk of unauthorized access.

Depending on the features available and the authentication method used, account-security measures may include:

  • Secure authentication
  • Password protection
  • Session management
  • Account access controls
  • Protection against unauthorized login attempts
  • Security monitoring and investigation of suspicious activity

Customers are responsible for maintaining the confidentiality of their account credentials, using strong and unique passwords where applicable, and promptly notifying Outbird if they suspect unauthorized access to their account.

If Outbird makes additional security features available, such as two-factor authentication, multi-factor authentication, or single sign-on, customers should enable them where appropriate.

5. Infrastructure Security

Outbird relies on infrastructure and service providers to operate and maintain its platform.

We take reasonable steps to maintain a secure environment through appropriate configuration, access restrictions, monitoring, updates, and maintenance.

Our infrastructure is built on Amazon Web Services (AWS), including:

  • Serverless application hosting (AWS Lambda) behind a managed API gateway
  • A managed NoSQL database (Amazon DynamoDB) for application data
  • Email delivery and mailbox integrations
  • AI processing services
  • Analytics and monitoring tools
  • Other third-party infrastructure required to provide the services

Security controls may vary depending on the provider, service, and type of information involved. We review our infrastructure and service providers as appropriate and take reasonable steps to address identified security risks.

We do not claim that our infrastructure or third-party providers are completely secure, and we cannot guarantee that unauthorized access, security incidents, or service interruptions will never occur.

6. Connected Email Accounts and Integrations

Outbird lets customers connect their own email mailbox — Gmail, Outlook, Zoho, Yahoo, or another SMTP/IMAP-compatible provider — to enable features such as campaign execution, email sending, follow-up automation, and reporting.

When a customer connects a mailbox, Outbird:

  • Authenticates using a provider-issued app password (or equivalent) rather than the mailbox's everyday login password.
  • Stores only the connection details needed to send and receive mail — email address, provider, and SMTP/IMAP host.
  • Sends emails or messages on the customer's behalf, where the customer has enabled this feature.
  • Accesses delivery, reply, or engagement information needed for campaign reporting.
  • Maintains the connection and performs actions requested by the customer.

Outbird aims to request and use only the permissions reasonably necessary for the selected functionality. The permissions available and requested may vary depending on the provider, integration, account type, and features enabled by the customer.

Customers should review the permissions requested by each integration before connecting an account and disconnect integrations they no longer use. Customers can also revoke Outbird’s access through the relevant third-party provider’s account settings.

Outbird does not claim that it can access every type of information available within a connected account. Access is limited by the permissions granted by the customer, the provider’s technical controls, and the functionality supported by the integration.

7. AI and Third-Party Service Providers

Outbird may use third-party providers to support services such as AI processing, application hosting, database and storage management, email delivery, analytics, monitoring, and customer support.

Depending on the functionality used, information may be processed by these providers on Outbird’s behalf. We aim to select providers that offer appropriate security and privacy safeguards and take reasonable steps to protect information shared with them.

Where required by applicable law or appropriate for the nature of the information, we may use contractual, technical, or organizational safeguards governing how third-party providers handle information.

Third-party providers may process information only as necessary to provide their services, maintain security, comply with legal obligations, or perform other permitted functions. Their handling of information may also be subject to their own privacy policies and terms.

For more information about how Outbird collects, uses, shares, and protects personal information, please see our Privacy Policy.

8. Monitoring and Incident Response

We take reasonable steps to monitor the availability, performance, and security of our systems and to investigate potential security issues.

If we become aware of a security incident that may affect customer information, we will assess the incident and, where appropriate, take reasonable steps to investigate, contain, mitigate, and address its effects.

Where required by applicable law or contractual obligations, we will notify affected customers or relevant authorities within the timeframe and through the method required by law or agreement.

Our response may include reviewing relevant logs and system activity, restricting access, addressing the underlying issue, restoring affected services, and taking steps to reduce the likelihood of a similar incident occurring again.

We do not guarantee that every security incident will be detected, prevented, or resolved immediately. Notifications will be provided based on the nature and impact of the incident and the applicable legal or contractual requirements.

9. Backups and Recovery

We take reasonable steps to support the availability and integrity of our services through backup and recovery practices appropriate to the systems we use.

Depending on the service and infrastructure provider, these practices may include:

  • Regular backups of relevant data
  • Protected backup storage
  • Access restrictions for backup systems
  • Procedures for recovering data or restoring services
  • Measures intended to reduce the risk of data loss or service interruption

Backup frequency, retention periods, and recovery capabilities may vary depending on the system, provider, and type of data involved. We do not guarantee that every item of information can be recovered or that services will be restored within a specific timeframe.

We periodically review our backup and recovery practices and take reasonable steps to address identified risks.

10. Data Retention and Deletion

We retain information only for as long as reasonably necessary to provide and maintain our services, meet legal and regulatory obligations, resolve disputes, enforce our agreements, prevent misuse, and protect our legitimate business interests.

When information is no longer required, we take reasonable steps to delete, anonymize, or otherwise dispose of it in accordance with our retention practices and applicable law.

Some information may remain in backups, security logs, or other records for a limited period after deletion where necessary for security, recovery, legal, or operational purposes. Such information will be handled in accordance with applicable retention requirements and our security practices.

Retention periods may vary depending on the type of information, the purpose for which it was collected, the customer’s account status, and applicable legal or contractual requirements.

For more information about how Outbird handles personal information, retention, and deletion requests, please see our Privacy Policy.

11. Employee and Contractor Access

Where applicable, employees, contractors, and other personnel who may access customer information are expected to handle that information confidentially and follow appropriate security practices.

Access to customer information is limited to what is reasonably necessary for an individual’s business responsibilities, support duties, or other authorized work.

Where appropriate, we may use confidentiality obligations, security guidance, access restrictions, and other measures to help protect customer information.

We take reasonable steps to ensure that access is removed or adjusted when it is no longer required, subject to applicable legal, operational, and security requirements.

We do not permit personnel to access customer information for unauthorized personal purposes or uses unrelated to their assigned responsibilities.

12. Responsible Disclosure

If you believe you have discovered a security vulnerability in Outbird, please report it responsibly so we can investigate and address it.

Security contact: info@outbird.dev

When reporting a potential vulnerability, please include:

  • A clear description of the issue
  • Steps to reproduce the issue
  • The affected feature, endpoint, or system
  • Any relevant technical details, screenshots, or logs
  • The potential impact, if known

Please avoid accessing, modifying, deleting, or downloading data that does not belong to you. Do not disrupt our services, conduct denial-of-service testing, or use automated tools that may affect system availability.

Please do not publicly disclose the vulnerability or share it with third parties before we have had a reasonable opportunity to investigate and address it.

We will review good-faith vulnerability reports and may contact you for additional information. We do not guarantee a specific response time, resolution time, reward, or outcome.

13. Security Questions

If you have questions about Outbird’s security practices, safeguards, or responsible-disclosure process, please contact us.

Security contact: info@outbird.dev

For privacy-related questions, requests, or concerns, please see our Privacy Policy or contact us using the details provided there.