Security and data residency
Level 7, 222 Exhibition Street, Melbourne VIC 3000, Australia
Australian core hosting
Reachable's application, primary customer database and backups are configured in Google Cloud Australian regions. Production campaign email for onboarded domains is sent through Amazon SES in Sydney (ap-southeast-2). Limited processing outside Australia may occur through billing, edge security, account email, sign-in, recipient networks and customer-enabled integrations as described in our Privacy Policy.
Access and separation
Tenant data is logically isolated with PostgreSQL row-level security. Workspace access requires an authenticated membership. Internal access is role-based and limited to operational, customer-requested support, abuse, security and legal need. Administrative actions, approvals, team changes and exports are audited; not every record read is individually logged.
Identity and secrets
Passwords are salted and hashed. Authenticator-app 2FA and session revocation are available. Production secrets are kept outside source control, access is restricted, and customer API keys are stored as hashes.
Sending safeguards
Billing entitlement, consent, suppression, sender identity, DKIM, custom MAIL FROM, DMARC, plan allowance and campaign approval checks run before campaign delivery. Bounce, complaint and unsubscribe events update suppression. Card numbers are handled by Stripe and are not stored by Reachable.
Resilience and response
Encrypted backups are retained in Australian cloud storage and restore drills are run regularly. Service and worker health are monitored. Suspected breaches are assessed under the Notifiable Data Breaches scheme and the DPA.
Reporting an issue
Report a suspected vulnerability or security incident to security@121group.io. Report a privacy matter to privacy@121group.io. Do not include unrelated customer records in the initial report.