Security, testing and what happens if we stop
Last updated October 1, 2026
What we will store, and for how long
| Data | How we'll handle it |
|---|---|
| Your SES-only AWS access key | Stored encrypted. Used only to send your newsletters through your SES account. Deleted within 24 hours after you cancel. |
| The API key Ghost uses to talk to the bridge | We'll store only a hash of it, not the key itself. |
| Newsletter content and recipient lists | Held only long enough to hand each batch to SES (and retry if SES is briefly unavailable). Deleted once SES accepts it, and never kept more than 24 hours. |
| Delivery events (recipient address, event type, time, message ID) | Kept for 30 days so Ghost can fetch them for its analytics and member status, then deleted. |
| Your email and payment record | Kept while you're a customer; payment records as long as the law requires. Card details stay with Stripe. |
During the pre-order we collect no AWS keys and no subscriber data. We will never ask for AWS root credentials, console passwords, or keys that can do more than send email through SES.
How your AWS key will be protected
- Least privilege. The setup guide will give you an exact IAM policy that only allows sending email (
ses:SendEmailandses:SendRawEmail) from your verified SES identity, using the configuration set that publishes events. A key with that policy can't read your mail, change your AWS account, or use other AWS services. - Encrypted at rest. Keys will be encrypted by the application before they reach our database, with an encryption key kept separately from the database, so a copy of the database alone wouldn't reveal them.
- Never shown or logged. Keys will be decrypted only in memory at send time. They won't be written to logs, shown back to you after you enter them, or sent anywhere except to AWS.
- You stay in control. You can deactivate the key in your own AWS console at any moment, without asking us. That immediately stops all sending through the bridge.
- Isolation between customers. Each Ghost site will get its own bridge key, and the bridge will be built so that one site's key can't read or send anything for another site. The automated tests will check this.
- Events are checked. Delivery events from SES arrive through Amazon SNS. The bridge will verify each message's signature and accept events only from the topic registered for your site.
Who writes and checks the code
The code is written by AI. Before we accept any customer's AWS key:
- Automated tests will cover the parts of the Mailgun API that Ghost uses (batch sending with per-recipient personalisation, the events feed, suppressions), plus security checks: one site can't see another's data, forged or replayed event messages are rejected, and AWS keys never appear in logs or responses. An end-to-end test will run a real self-hosted Ghost install against Amazon's SES mailbox simulator (delivered, bounced and complained addresses) and confirm the events show up in Ghost. The tests will run before every deploy, and a failing test will block it.
- An independent security review of the design and the code by a separate AI security reviewer, not the agent that wrote it. Every finding will be fixed, or written down with the reason it was accepted, before the beta starts. We'll publish a short summary of what the review found and what we fixed.
- A small beta with users who try to break it, starting with pre-order customers who opt in. We'll suggest starting with a test list and the SES mailbox simulator before sending to real subscribers.
If something goes wrong
If we find or suspect that stored keys or subscriber data have been exposed, we'll email every affected customer within 72 hours of finding out, explain what happened, and ask you to rotate your AWS key (only you can do that). We'll be able to pause sending for one site, or for everyone, while we investigate. Report security issues to support@cevict.ai.
Will you still be around?
Honestly: CEVICT is a small studio and this is a new product, so we can't promise it will run for years. Here's what we do promise:
- Before launch: if fewer than 3 people pre-order by October 30, 2026, or it hasn't shipped by December 1, 2026, everyone gets a full refund.
- After launch: at least 60 days' notice by email before we shut the service down, a refund of any unused prepaid time, and deletion of all stored keys and data within 7 days of shutdown (except payment records we must keep by law). This is in our terms.
- No lock-in: the bridge speaks Mailgun's API, so leaving means pointing Ghost's bulk-email settings back at Mailgun or at a self-hosted open-source proxy. Our guide lists those options.
Not decided yet
- Whether the bridge's source code will be published.
- An uptime target or service-level agreement. There isn't one yet.
Questions about any of this: support@cevict.ai. See also our privacy policy.