Security
Built to protect the accounts you connect
Tantra sends from your own mailboxes and social accounts, so protecting those credentials, and the people you contact, is the core of how the platform is built.
Credentials and access
Encryption of connected credentials
AI provider keys and sign-in tokens, and the Google service account key you upload, are encrypted with AES-256 before storage and are never returned to the browser.
API keys stored as hashes
An API key is displayed once at creation and stored only as a hash. Keys can carry an expiry date and can be revoked at any time. Each key has account-level access, so issue one key per integration.
Authentication
Sign-in is handled by Clerk, a dedicated identity provider, so Tantra never stores your password.
You stay in control of Google access
A Google Workspace admin grants domain-wide delegation to your own service account with the exact scopes listed in our setup guide, and can revoke it from the Google Admin console at any time.
Protecting recipients and your sender reputation
No open-tracking pixels
Tantra never inserts an open pixel. Click tracking is off unless you turn it on.
One-click unsubscribe
Every campaign email carries standard one-click unsubscribe headers and an unsubscribe footer by default.
Suppression before every send
Unsubscribed and suppressed contacts are never enrolled, and a hard bounce suppresses the address automatically.
Sending limits per account
Per-mailbox daily and hourly caps, and per-account LinkedIn and WhatsApp limits, keep volume within conservative ranges.
Infrastructure and data
Hosting
The Tantra API and queues run on Microsoft Azure, Central India region (Pune). Traffic is served over TLS through Cloudflare.
Payments
Payments are processed by Dodo Payments. Card details never reach Tantra's servers.
Service providers
Every provider that processes data for Tantra is named in our Privacy Policy, with its purpose and location.
Data requests and agreements
Deletion and access requests, and Data Processing Agreement requests, go to [email protected].
Report a vulnerability
If you believe you have found a security issue, email [email protected] with the subject line “Security report”. Reports are reviewed by Adithya Murali, Founder. Please give us reasonable time to fix an issue before disclosing it.