Security & Compliance | BounceZero
CSA STAR Listed - GDPR Compliant - UK Ltd Registered

Security You Can Trust With Your Contact Data

Every email you verify with BounceZero is processed under strict security controls. Here's exactly how we handle your data.

How We Handle Your Data

End-to-end protection from the moment your data enters our pipeline to the moment it leaves.

Data in Transit

TLS 1.3 encryption on all API connections. Your email list never travels unencrypted.

Data at Rest

Encryption at rest. Infrastructure locations and transfer safeguards are documented in the Privacy Policy and DPA.

Data Retention

Bulk job results kept 90 days then permanently deleted. Single-check results purged after 24 hours.

GDPR & Privacy Compliance

BounceZero Ltd is a UK registered company (No. 17153835) operating under UK GDPR. We act as a data processor when verifying your contact lists.

We do not sell, share, or use your email data for any purpose other than verification. Your data is yours - we just tell you which addresses are real.

Compliance Checklist

  • UK GDPR compliant (UK Ltd, No. 17153835)
  • Infrastructure and subprocessors documented in the DPA
  • No third-party data sharing
  • Right to erasure - request via [email protected]
  • Data Processing Agreement (DPA) available on request
  • API keys are hashed - not stored in plaintext
  • Webhook signing secrets to verify payload integrity
  • CSA STAR Level 1 - publicly listed in the registry

Infrastructure Security

Multiple layers of protection across every component of our stack.

API Authentication

Bearer token auth. API keys are SHA-256 hashed in the database.

Rate Limiting

Per-endpoint rate limits prevent abuse and protect your account.

Webhook Signatures

HMAC-SHA256 signed payloads. Verify every webhook delivery.

No Plaintext Storage

Email addresses in bulk jobs are never logged to disk.

Audit Logging

All credential reveals and sensitive actions are audit-logged.

UK Company

Incorporated in England & Wales. Accountable to UK regulatory framework.

Certifications & Registries

Independently verifiable third-party registrations - not self-declared. Click any badge to verify.

How BounceZero Support Contacts You

Attackers impersonate support teams. These rules never change, so you can always tell the difference.

We will never ask you for any of these

  • Your password, on any channel, for any reason.
  • A support PIN, verification code, or two-factor code.
  • Your API key. We can see what we need without it, and we can issue you a new one.
  • Card numbers or full billing details over chat or email.
  • Access to a different account, or credentials belonging to a colleague.
  • Remote access to your machine, or installation of any software.

Every ticket lives in your dashboard

If we have an open case with you, you can see it signed in to your account. A conversation that exists only in your inbox or a chat window is not from us.

A reference number proves nothing

Anyone can invent a case ID and quote it to you. Verify it the other way round: sign in and look for the ticket yourself. If it is not there, the request is not ours.

We only email from bouncezero.io

Our mail is SPF, DKIM and DMARC authenticated. Check the sending domain, not the display name — a display name costs an attacker nothing to fake.

Urgency is the tell

Warnings that your domain, account or email is at risk unless you act immediately are pressure tactics. Nothing we need from you is ever time-critical in that way.

Contacted by someone claiming to be BounceZero support? Forward it to [email protected] and do not reply to them.

Found a Security Vulnerability?

We take security seriously. Email [email protected] and we'll respond within 48 hours.

Report to [email protected]

Legal & Policy Documents

Follow BounceZero

BounceZero company & trust

Verify our credentials, read honest reviews, compare with alternatives