CEVICT

Security, testing and what happens if we stop

Last updated October 1, 2026

Nothing here is built yet. SES Bridge for Ghost is a pre-order. This page describes how we will build and run it, written down before we write any code so you can hold us to it. If any of this changes, we'll update this page first and email pre-order customers.

What we will store, and for how long

DataHow we'll handle it
Your SES-only AWS access keyStored encrypted. Used only to send your newsletters through your SES account. Deleted within 24 hours after you cancel.
The API key Ghost uses to talk to the bridgeWe'll store only a hash of it, not the key itself.
Newsletter content and recipient listsHeld only long enough to hand each batch to SES (and retry if SES is briefly unavailable). Deleted once SES accepts it, and never kept more than 24 hours.
Delivery events (recipient address, event type, time, message ID)Kept for 30 days so Ghost can fetch them for its analytics and member status, then deleted.
Your email and payment recordKept while you're a customer; payment records as long as the law requires. Card details stay with Stripe.

During the pre-order we collect no AWS keys and no subscriber data. We will never ask for AWS root credentials, console passwords, or keys that can do more than send email through SES.

How your AWS key will be protected

Who writes and checks the code

The code is written by AI. Before we accept any customer's AWS key:

  1. Automated tests will cover the parts of the Mailgun API that Ghost uses (batch sending with per-recipient personalisation, the events feed, suppressions), plus security checks: one site can't see another's data, forged or replayed event messages are rejected, and AWS keys never appear in logs or responses. An end-to-end test will run a real self-hosted Ghost install against Amazon's SES mailbox simulator (delivered, bounced and complained addresses) and confirm the events show up in Ghost. The tests will run before every deploy, and a failing test will block it.
  2. An independent security review of the design and the code by a separate AI security reviewer, not the agent that wrote it. Every finding will be fixed, or written down with the reason it was accepted, before the beta starts. We'll publish a short summary of what the review found and what we fixed.
  3. A small beta with users who try to break it, starting with pre-order customers who opt in. We'll suggest starting with a test list and the SES mailbox simulator before sending to real subscribers.

If something goes wrong

If we find or suspect that stored keys or subscriber data have been exposed, we'll email every affected customer within 72 hours of finding out, explain what happened, and ask you to rotate your AWS key (only you can do that). We'll be able to pause sending for one site, or for everyone, while we investigate. Report security issues to support@cevict.ai.

Will you still be around?

Honestly: CEVICT is a small studio and this is a new product, so we can't promise it will run for years. Here's what we do promise:

Not decided yet

Questions about any of this: support@cevict.ai. See also our privacy policy.